Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The virtualization software XEN was updated to version 4.3.3 and also to
fix bugs and security issues.
Security issues fixed: CVE-2015-0361: XSA-116: xen: xen crash due to use
after free on hvm guest teardown
CVE-2014-9065, CVE-2014-9066: XSA-114: xen: p2m lock starvation
CVE-2014-9030: XSA-113: Guest effectable page reference leak in
MMU_MACHPHYS_UPDATE handling
CVE-2014-8867: XSA-112: xen: Insufficient bounding of "REP MOVS" to MMIO
emulated inside the hypervisor
CVE-2014-8866: XSA-111: xen: Excessive checking in compatibility mode
hypercall argument translation
CVE-2014-8595: XSA-110: xen: Missing privilege level checks in x86
emulation of far branches
CVE-2014-8594: XSA-109: xen: Insufficient restrictions on certain MMU
update hypercalls
CVE-2013-3495: XSA-59: xen: Intel VT-d Interrupt Remapping engines can be
evaded by native NMI interrupts
CVE-2014-5146, CVE-2014-5149: xen: XSA-97 Long latency virtual-mmu
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- openSUSE 13.1:
zypper in -t patch openSUSE-2015-113=1
To bring your system up-to-date, use "zypper patch".
- openSUSE 13.1 (i586 x86_64):
xen-debugsource-4.3.3_04-34.1
xen-devel-4.3.3_04-34.1
xen-kmp-default-4.3.3_04_k3.11.10_25-34.1
xen-kmp-default-debuginfo-4.3.3_04_k3.11.10_25-34.1
xen-kmp-desktop-4.3.3_04_k3.11.10_25-34.1
xen-kmp-desktop-debuginfo-4.3.3_04_k3.11.10_25-34.1
xen-libs-4.3.3_04-34.1
xen-libs-debuginfo-4.3.3_04-34.1
xen-tools-domU-4.3.3_04-34.1
xen-tools-domU-debuginfo-4.3.3_04-34.1
- openSUSE 13.1 (x86_64):
xen-4.3.3_04-34.1
xen-doc-html-4.3.3_04-34.1
xen-libs-32bit-4.3.3_04-34.1
xen-libs-debuginfo-32bit-4.3.3_04-34.1
xen-tools-4.3.3_04-34.1
xen-tools-debuginfo-4.3.3_04-34.1
xen-xend-tools-4.3.3_04-34.1
xen-xend-tools-debuginfo-4.3.3_04-34.1
- openSUSE 13.1 (i586):
xen-kmp-pae-4.3.3_04_k3.11.10_25-34.1
xen-kmp-pae-debuginfo-4.3.3_04_k3.11.10_25-34.1
https://www.suse.com/security/cve/CVE-2013-3495.html
https://www.suse.com/security/cve/CVE-2014-5146.html
https://www.suse.com/security/cve/CVE-2014-5149.html
https://www.suse.com/security/cve/CVE-2014-8594.html
https://www.suse.com/security/cve/CVE-2014-8595.html
https://www.suse.com/security/cve/CVE-2014-8866.html
https://www.suse.com/security/cve/CVE-2014-8867.html
https://www.suse.com/security/cve/CVE-2014-9030.html
https://www.suse.com/security/cve/CVE-2014-9065.html
https://www.suse.com/security/cve/CVE-2014-9066.html
https://www.suse.com/security/cve/CVE-2015-0361.html
https://bugzilla.suse.com/show_bug.cgi?id=826717
https://bugzilla.suse.com/show_bug.cgi?id=866902
https://bugzilla.suse.com/show_bug.cgi?id=882089
https://bugzilla.suse.com/show_bug.cgi?id=889526
https://bugzilla.suse.com/show_bug.cgi?id=900292
https://bugzilla.suse.com/show_bug.cgi?id=901317
https://bugzilla.suse.com/show_bug.cgi?id=903357
https://bugzilla.suse.com/show_bug.cgi?id=903359
https://bugzilla.suse.com/show_bug.cgi?id=90...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.