Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2328-1

Опубликовано: 10 июн. 2026
Источник: suse-cvrf

Описание

Security update for xen

This update for xen fixes the following issues:

  • CVE-2026-42487: x86 HVM I/O port list traversal (bsc#1266952).
  • CVE-2026-42488: x86: mismatched mapcache metadata (bsc#1266955).
  • CVE-2026-42489,CVE-2026-42490: domctl lock open to abuse (bsc#1266953).

Список пакетов

Image SLES15-SP5-Azure-3P
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Basic
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Standard
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Hardened-BYOS-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Hardened-BYOS-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Hardened-BYOS-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Azure-3P
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-BYOS-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-BYOS-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-BYOS-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Hardened-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAP-Hardened-GCE
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAPCAL-Azure
xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAPCAL-EC2
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
Image SLES15-SP5-SAPCAL-GCE
xen-libs-4.17.6_12-150500.3.73.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
xen-4.17.6_12-150500.3.73.1
xen-devel-4.17.6_12-150500.3.73.1
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
xen-tools-xendomains-wait-disk-4.17.6_12-150500.3.73.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
xen-4.17.6_12-150500.3.73.1
xen-devel-4.17.6_12-150500.3.73.1
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
xen-tools-xendomains-wait-disk-4.17.6_12-150500.3.73.1
SUSE Linux Enterprise Micro 5.5
xen-libs-4.17.6_12-150500.3.73.1
SUSE Linux Enterprise Server 15 SP5-LTSS
xen-4.17.6_12-150500.3.73.1
xen-devel-4.17.6_12-150500.3.73.1
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
xen-tools-xendomains-wait-disk-4.17.6_12-150500.3.73.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
xen-4.17.6_12-150500.3.73.1
xen-devel-4.17.6_12-150500.3.73.1
xen-libs-4.17.6_12-150500.3.73.1
xen-tools-4.17.6_12-150500.3.73.1
xen-tools-domU-4.17.6_12-150500.3.73.1
xen-tools-xendomains-wait-disk-4.17.6_12-150500.3.73.1

Описание

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.


Затронутые продукты
Image SLES15-SP5-Azure-3P:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Basic:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Standard:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-Azure:xen-libs-4.17.6_12-150500.3.73.1

Ссылки

Описание

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache.


Затронутые продукты
Image SLES15-SP5-Azure-3P:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Basic:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Standard:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-Azure:xen-libs-4.17.6_12-150500.3.73.1

Ссылки

Описание

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.


Затронутые продукты
Image SLES15-SP5-Azure-3P:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Basic:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Standard:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-Azure:xen-libs-4.17.6_12-150500.3.73.1

Ссылки

Описание

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.


Затронутые продукты
Image SLES15-SP5-Azure-3P:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Basic:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-Azure-Standard:xen-libs-4.17.6_12-150500.3.73.1
Image SLES15-SP5-BYOS-Azure:xen-libs-4.17.6_12-150500.3.73.1

Ссылки