SUSE-SU-2026:4090-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4090-1
SUSE-SU-2026:4090-1
Summary: Security update for xen
Details: This update for xen fixes the following issues: Update to version 4.20.3 (jsc#PED-8907). Security issues fixed: - CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). - CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). - CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). - CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). - CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). - CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). - CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). - CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). - CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). - CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). - CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). - CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). - CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841). - pygrub is only supported in de-privileged mode (bsc#1271947). Non security issue fixed: - Xen: Missing upstream bug fixes (bsc#1027519).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264090-1/, https://bugzilla.suse.com/1027519, https://bugzilla.suse.com/1271528, https://bugzilla.suse.com/1271530, https://bugzilla.suse.com/1271531, https://bugzilla.suse.com/1271532, https://bugzilla.suse.com/1271533, https://bugzilla.suse.com/1271534, https://bugzilla.suse.com/1271535, https://bugzilla.suse.com/1271536, https://bugzilla.suse.com/1271537, https://bugzilla.suse.com/1271538, https://bugzilla.suse.com/1271539, https://bugzilla.suse.com/1271947, https://bugzilla.suse.com/1276838, https://bugzilla.suse.com/1276839, https://bugzilla.suse.com/1276841, https://www.suse.com/security/cve/CVE-2026-42493, https://www.suse.com/security/cve/CVE-2026-42494, https://www.suse.com/security/cve/CVE-2026-42495, https://www.suse.com/security/cve/CVE-2026-62423, https://www.suse.com/security/cve/CVE-2026-62424, https://www.suse.com/security/cve/CVE-2026-62425, https://www.suse.com/security/cve/CVE-2026-62426, https://www.suse.com/security/cve/CVE-2026-62427, https://www.suse.com/security/cve/CVE-2026-62428, https://www.suse.com/security/cve/CVE-2026-62429, https://www.suse.com/security/cve/CVE-2026-62430, https://www.suse.com/security/cve/CVE-2026-62431, https://www.suse.com/security/cve/CVE-2026-62432, https://www.suse.com/security/cve/CVE-2026-62433, https://www.suse.com/security/cve/CVE-2026-62434, https://www.suse.com/security/cve/CVE-2026-62437, https://www.suse.com/security/cve/CVE-2026-79602, https://www.suse.com/security/cve/CVE-2026-79603
Affected packages
Package
Name: xen
Purl: pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
Affected ranges
Type: ECOSYSTEM
Events:
