Описание
Security update for xen
This update for xen fixes the following issues:
Update to Xen 4.20.2 (jsc#PED-8907).
Security issues fixed:
- CVE-2025-58149: incorrect removal of permissions on PCI device unplug allows PV guests to access memory of devices no longer assigned to it (XSA-476, bsc#1252692).
Other issues fixed:
- Failure to restart xenstored (bsc#1254180).
Список пакетов
Image SLES15-SP7-Azure-3P
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Azure-Basic
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Azure-Standard
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-Aliyun
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-GDC
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-EC2-ECS-HVM
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-GCE-3P
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-HPC-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-HPC-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-HPC-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-HPC-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Hardened-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Hardened-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Hardened-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Azure-3P
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Azure-LI-BYOS-Production
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Azure-VLI-BYOS-Production
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-GCE-3P
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Hardened-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAP-Hardened-GCE
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAPCAL-Azure
xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAPCAL-EC2
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
Image SLES15-SP7-SAPCAL-GCE
xen-libs-4.20.2_02-150700.3.19.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
xen-libs-4.20.2_02-150700.3.19.1
xen-tools-domU-4.20.2_02-150700.3.19.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
xen-4.20.2_02-150700.3.19.1
xen-devel-4.20.2_02-150700.3.19.1
xen-tools-4.20.2_02-150700.3.19.1
xen-tools-xendomains-wait-disk-4.20.2_02-150700.3.19.1
Ссылки
- Link for SUSE-SU-2025:4419-1
- E-Mail link for SUSE-SU-2025:4419-1
- SUSE Security Ratings
- SUSE Bug 1252692
- SUSE Bug 1254180
- SUSE CVE CVE-2025-58149 page
Описание
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assigned to the domain. For PV domains the permission leak allows the domain itself to map the memory in the page-tables. For HVM it would require a compromised device model or stubdomain to map the leaked memory into the HVM domain p2m.
Затронутые продукты
Image SLES15-SP7-Azure-3P:xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Azure-Basic:xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-Azure-Standard:xen-libs-4.20.2_02-150700.3.19.1
Image SLES15-SP7-BYOS-Azure:xen-libs-4.20.2_02-150700.3.19.1
Ссылки
- CVE-2025-58149
- SUSE Bug 1252692