Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: DSA-4602-1 Critical: Xen Hypervisor Denial Of Service

debian
Calendar Grey January 13, 2020
Debian Logo
The Ubuntu Security Notice USN-5003-1 outlines several weaknesses in the OpenSSL library that may result in critical security concerns.
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information leaks

Summary

Multiple vulnerabilities have been discovered in the Xen hypervisor, which
could result in denial of service, guest-to-host privilege escalation or
information leaks.

In addition this update provides mitigations for the "TSX Asynchronous Abort"
speculative side channel attack. For additional information please refer to
https://xenbits.xen.org/xsa/advisory-305.html

For the oldstable distribution (stretch), these problems have been fixed
in version 4.8.5.final+shim4.10.4-1+deb9u12. Note that this will be the
last security update for Xen in the oldstable distribution; upstream
support for the 4.8.x branch ended by the end of December 2019. If you
rely on security support for your Xen installation an update to the
stable distribution (buster) is recommended.

For the stable distribution (buster), these problems have been fixed in
version 4.11.3+24-g14b62ab3e5-1~deb10u1.

We recommend that you upgrade your xen packages.

For the detailed security status of xen please refer to
its security tracker page at:
h...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xen
CVE ID: CVE-2019-17349 CVE-2019-17350 CVE-2019-18420 CVE-2019-18421

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here