SUSE-SU-2021:1648-1
Dashboard / Vulnerabilities / SUSE-SU-2021:1648-1
SUSE-SU-2021:1648-1
Summary: Security update for xen
Details: This update for xen fixes the following issues: Security issue fixed: - CVE-2021-28689: Fixed some x86 speculative vulnerabilities with bare (non-shim) 32-bit PV guests (XSA-370) (bsc#1185104) - Make sure xencommons is in a format as expected by fillup. (bsc#1185682) Each comment needs to be followed by an enabled key. Otherwise fillup will remove manually enabled key=value pairs, along with everything that looks like a stale comment, during next pkg update - A recent systemd update caused a regression in xenstored.service systemd now fails to track units that use systemd-notify (bsc#1183790) - Added a delay between the call to systemd-notify and the final exit of the wrapper script (bsc#1185021, bsc#1185196)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20211648-1/, https://bugzilla.suse.com/1183790, https://bugzilla.suse.com/1185021, https://bugzilla.suse.com/1185104, https://bugzilla.suse.com/1185196, https://bugzilla.suse.com/1185682, https://www.suse.com/security/cve/CVE-2021-28689
Affected packages
Package
Name: xen
Purl: pkg:rpm/suse/xen&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
