SUSE-SU-2018:2081-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2081-1
SUSE-SU-2018:2081-1
Summary: Security update for xen
Details: This update for xen fixes the following issues: Security issues fixed: - CVE-2018-12891: Fix preemption checks bypass in x86 PV MM handling (XSA-264) (bsc#1097521). - CVE-2018-12892: Fix libxl failure to honour readonly flag on HVM emulated SCSI disks (XSA-266) (bsc#1097523). - CVE-2018-12893: Fix #DB exception safety check that could be triggered by a guest (XSA-265) (bsc#1097522). - CVE-2018-11806: Fix heap buffer overflow while reassembling fragmented datagrams (bsc#1096224). - CVE-2018-3665: Fix lazy FP Save/Restore (XSA-267) (bsc#1095242). Bug fixes: - bsc#1027519: Update to Xen 4.7.6 bug fix only release. - bsc#1087289: Xen BUG at sched_credit.c:1663. - bsc#1094725: `virsh blockresize` does not work with Xen qdisks.
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182081-1/, https://bugzilla.suse.com/1027519, https://bugzilla.suse.com/1087289, https://bugzilla.suse.com/1094725, https://bugzilla.suse.com/1095242, https://bugzilla.suse.com/1096224, https://bugzilla.suse.com/1097521, https://bugzilla.suse.com/1097522, https://bugzilla.suse.com/1097523, https://www.suse.com/security/cve/CVE-2018-11806, https://www.suse.com/security/cve/CVE-2018-12891, https://www.suse.com/security/cve/CVE-2018-12892, https://www.suse.com/security/cve/CVE-2018-12893, https://www.suse.com/security/cve/CVE-2018-3665
Affected packages
Package
Name: xen
Purl: pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
