SUSE-SU-2018:0909-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0909-1
SUSE-SU-2018:0909-1
Summary: Security update for xen
Details: This update for xen fixes the following issues: Update to Xen 4.7.5 bug fix only release (bsc#1027519) Security issues fixed: - CVE-2018-7540: Fixed DoS via non-preemptable L3/L4 pagetable freeing (XSA-252) (bsc#1080635) - CVE-2018-7541: A grant table v2 -> v1 transition may crash Xen (XSA-255) (bsc#1080662) - CVE-2017-5753,CVE-2017-5715,CVE-2017-5754 Fixed information leaks via side effects of speculative execution (XSA-254). Includes Spectre v2 mitigation. (bsc#1074562) - Preserve xen-syms from xen-dbg.gz to allow processing vmcores with crash(1) (bsc#1087251) - Xen HVM: Fixed unchecked MSR access error (bsc#1072834) - Add script, udev rule and systemd service to watch for vcpu online/offline events in a HVM domU They are triggered via xl vcpu-set domU N (fate#324965) - Make sure tools and tools-domU require libs from the very same build
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180909-1/, https://bugzilla.suse.com/1027519, https://bugzilla.suse.com/1072834, https://bugzilla.suse.com/1074562, https://bugzilla.suse.com/1080635, https://bugzilla.suse.com/1080662, https://bugzilla.suse.com/1087251, https://www.suse.com/security/cve/CVE-2017-5715, https://www.suse.com/security/cve/CVE-2017-5753, https://www.suse.com/security/cve/CVE-2017-5754, https://www.suse.com/security/cve/CVE-2018-7540, https://www.suse.com/security/cve/CVE-2018-7541
Affected packages
Package
Name: xen
Purl: pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
