Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0589-1

Опубликовано: 20 фев. 2026
Источник: suse-cvrf

Описание

Security update for xen

This update for xen fixes the following issues:

  • CVE-2025-58150: buffer overrun with shadow paging + tracing (XSA-477) (bsc#1256745).
  • CVE-2026-23553: incomplete IBPB for vCPU isolation (XSA-479) (bsc#1256747).

Список пакетов

Image SLES15-SP7-BYOS-EC2
xen-libs-4.20.2_06-150700.3.25.1
xen-tools-domU-4.20.2_06-150700.3.25.1
Image SLES15-SP7-Hardened-BYOS-EC2
xen-libs-4.20.2_06-150700.3.25.1
xen-tools-domU-4.20.2_06-150700.3.25.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
xen-libs-4.20.2_06-150700.3.25.1
xen-tools-domU-4.20.2_06-150700.3.25.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
xen-4.20.2_06-150700.3.25.1
xen-devel-4.20.2_06-150700.3.25.1
xen-tools-4.20.2_06-150700.3.25.1
xen-tools-xendomains-wait-disk-4.20.2_06-150700.3.25.1

Описание

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.


Затронутые продукты
Image SLES15-SP7-BYOS-EC2:xen-libs-4.20.2_06-150700.3.25.1
Image SLES15-SP7-BYOS-EC2:xen-tools-domU-4.20.2_06-150700.3.25.1
Image SLES15-SP7-Hardened-BYOS-EC2:xen-libs-4.20.2_06-150700.3.25.1
Image SLES15-SP7-Hardened-BYOS-EC2:xen-tools-domU-4.20.2_06-150700.3.25.1

Ссылки

Описание

In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between vCPUs, this prevents the guest kernel correctly isolating between tasks. Consider: 1) vCPU runs on CPU A, running task 1. 2) vCPU moves to CPU B, idle gets scheduled on A. Xen skips IBPB. 3) On CPU B, guest kernel switches from task 1 to 2, issuing IBPB. 4) vCPU moves back to CPU A. Xen skips IBPB again. Now, task 2 is running on CPU A with task 1's training still in the BTB.


Затронутые продукты
Image SLES15-SP7-BYOS-EC2:xen-libs-4.20.2_06-150700.3.25.1
Image SLES15-SP7-BYOS-EC2:xen-tools-domU-4.20.2_06-150700.3.25.1
Image SLES15-SP7-Hardened-BYOS-EC2:xen-libs-4.20.2_06-150700.3.25.1
Image SLES15-SP7-Hardened-BYOS-EC2:xen-tools-domU-4.20.2_06-150700.3.25.1

Ссылки
Уязвимость SUSE-SU-2026:0589-1