Описание
Security update for xen
This update for xen fixes the following issues:
- CVE-2026-42487: xen: x86 HVM I/O port list traversal (XSA-491) (bsc#1266952).
- CVE-2026-42488: xen: x86: mismatched mapcache metadata (XSA-494) (bsc#1266955).
- CVE-2026-42489,CVE-2026-42490: xen: domctl lock open to abuse (XSA-492) (bsc#1266953).
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:2668-1
- E-Mail link for SUSE-SU-2026:2668-1
- SUSE Security Ratings
- SUSE Bug 1266952
- SUSE Bug 1266953
- SUSE Bug 1266955
- SUSE CVE CVE-2026-42487 page
- SUSE CVE CVE-2026-42488 page
- SUSE CVE CVE-2026-42489 page
- SUSE CVE CVE-2026-42490 page
Описание
HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.
Затронутые продукты
Ссылки
- CVE-2026-42487
- SUSE Bug 1266952
Описание
Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache.
Затронутые продукты
Ссылки
- CVE-2026-42488
- SUSE Bug 1266955
Описание
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.
Затронутые продукты
Ссылки
- CVE-2026-42489
- SUSE Bug 1266953
Описание
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.
Затронутые продукты
Ссылки
- CVE-2026-42490
- SUSE Bug 1266953