Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

openSUSE 13.1 SUSE-SU-2015:1964-1 Important: Xen DoS Risks

opensuse
Calendar Grey November 12, 2015
Scroller Opensuse
A significant openSUSE enhancement addresses various vulnerabilities in the xen framework, notably the risk of Denial-of-Service incidents.
An update that solves 12 vulnerabilities and has two fixes An update that solves 12 vulnerabilities and has two fixes An update that solves 12 vulnerabilities and has two fixes is ...

Description

xen was updated to fix 13 security issues.

These security issues were fixed:

- CVE-2015-7972: Populate-on-demand balloon size inaccuracy can crash

guests (bsc#951845).

- CVE-2015-7969: Leak of main per-domain vcpu pointer array (DoS)

(bsc#950703).

- CVE-2015-7969: Leak of per-domain profiling-related vcpu pointer array

(DoS) (bsc#950705).

- CVE-2015-7971: Some pmu and profiling hypercalls log without rate

limiting (bsc#950706).

- CVE-2015-4037: Insecure temporary file use in /net/slirp.c (bsc#932267).

- CVE-2014-0222: Validate L2 table size to avoid integer overflows

(bsc#877642).

- CVE-2015-7835: Uncontrolled creation of large page mappings by PV guests

(bsc#950367).

- CVE-2015-7311: libxl fails to honour readonly flag on disks with

qemu-xen (bsc#947165).

- CVE-2015-5165: QEMU leak of uninitialized heap memory in rtl8139 device

model (bsc#939712).

- CVE-2015-5166: Use after free in QEMU/Xen block unplug...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-729=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.1 (i586 x86_64):

xen-debugsource-4.3.4_06-50.1

xen-devel-4.3.4_06-50.1

xen-kmp-default-4.3.4_06_k3.11.10_29-50.1

xen-kmp-default-debuginfo-4.3.4_06_k3.11.10_29-50.1

xen-kmp-desktop-4.3.4_06_k3.11.10_29-50.1

xen-kmp-desktop-debuginfo-4.3.4_06_k3.11.10_29-50.1

xen-libs-4.3.4_06-50.1

xen-libs-debuginfo-4.3.4_06-50.1

xen-tools-domU-4.3.4_06-50.1

xen-tools-domU-debuginfo-4.3.4_06-50.1

- openSUSE 13.1 (x86_64):

xen-4.3.4_06-50.1

xen-doc-html-4.3.4_06-50.1

xen-libs-32bit-4.3.4_06-50.1

xen-libs-debuginfo-32bit-4.3.4_06-50.1

xen-tools-4.3.4_06-50.1

xen-tools-debuginfo-4.3.4_06-50.1

xen-xend-tools-4.3.4_06-50.1

xen-xend-tools-debuginfo-4.3.4_06-50.1

- openSUSE 13.1 (i586):

xen-kmp-pae-4.3.4_06_k3.11.10_29-50.1

xen-kmp-pae-debuginfo-4.3.4_06_k3.11.10_29-50.1

References

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2015-4037.html

https://www.suse.com/security/cve/CVE-2015-5154.html

https://www.suse.com/security/cve/CVE-2015-5165.html

https://www.suse.com/security/cve/CVE-2015-5166.html

https://www.suse.com/security/cve/CVE-2015-5239.html

https://www.suse.com/security/cve/CVE-2015-6815.html

https://www.suse.com/security/cve/CVE-2015-7311.html

https://www.suse.com/security/cve/CVE-2015-7835.html

https://www.suse.com/security/cve/CVE-2015-7969.html

https://www.suse.com/security/cve/CVE-2015-7971.html

https://www.suse.com/security/cve/CVE-2015-7972.html

https://bugzilla.suse.com/show_bug.cgi?id=877642

https://bugzilla.suse.com/show_bug.cgi?id=932267

https://bugzilla.suse.com/show_bug.cgi?id=938344

https://bugzilla.suse.com/show_bug.cgi?id=939709

https://bugzilla.suse.com/show_bug.cgi?id=939712

https://bugzilla.suse.com/show_bug.cgi?id=941074

https://bugzilla.suse.com/show_bug.cgi?id=944463

https://bugzilla.suse.com/show_bug.cgi?i...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1964-1
Rating: important
Affected Products: openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.