Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 42.3: 2018:0459-1 Critical: Xen DoS Attack Resolution

opensuse
Calendar Grey February 16, 2018
Dist Opensuse Esm H88
An important patch for Fedora resolves 12 vulnerabilities in KVM, improving system integrity and performance with protections against data breaches.
An update that solves 10 vulnerabilities and has three fixes is now available.

Description

This update for xen fixes several issues.

These security issues were fixed:

- CVE-2017-5753, CVE-2017-5715, CVE-2017-5754: Prevent information leaks

via side effects of speculative execution, aka "Spectre" and "Meltdown"

attacks (bsc#1074562, bsc#1068032)

- CVE-2017-15595: x86 PV guest OS users were able to cause a DoS

(unbounded recursion, stack consumption, and hypervisor crash) or

possibly gain privileges via crafted page-table stacking (bsc#1061081)

- CVE-2017-17566: Prevent PV guest OS users to cause a denial of service

(host OS crash) or gain host OS privileges in shadow mode by mapping a

certain auxiliary page (bsc#1070158).

- CVE-2017-17563: Prevent guest OS users to cause a denial of service

(host OS crash) or gain host OS privileges by leveraging an incorrect

mask for reference-count overflow checking in shadow mode (bsc#1070159).

- CVE-2017-17564: Prevent guest OS users to cause a denial of service

(host...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-169=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (x86_64):

xen-4.9.1_08-16.1

xen-debugsource-4.9.1_08-16.1

xen-devel-4.9.1_08-16.1

xen-doc-html-4.9.1_08-16.1

xen-libs-4.9.1_08-16.1

xen-libs-debuginfo-4.9.1_08-16.1

xen-tools-4.9.1_08-16.1

xen-tools-debuginfo-4.9.1_08-16.1

xen-tools-domU-4.9.1_08-16.1

xen-tools-domU-debuginfo-4.9.1_08-16.1

References

https://www.suse.com/security/cve/CVE-2017-15595.html

https://www.suse.com/security/cve/CVE-2017-17563.html

https://www.suse.com/security/cve/CVE-2017-17564.html

https://www.suse.com/security/cve/CVE-2017-17565.html

https://www.suse.com/security/cve/CVE-2017-17566.html

https://www.suse.com/security/cve/CVE-2017-18030.html

https://www.suse.com/security/cve/CVE-2017-5715.html

https://www.suse.com/security/cve/CVE-2017-5753.html

https://www.suse.com/security/cve/CVE-2017-5754.html

https://www.suse.com/security/cve/CVE-2018-5683.html

https://bugzilla.suse.com/1027519

https://bugzilla.suse.com/1035442

https://bugzilla.suse.com/1051729

https://bugzilla.suse.com/1061081

https://bugzilla.suse.com/1067317

https://bugzilla.suse.com/1068032

https://bugzilla.suse.com/1070158

https://bugzilla.suse.com/1070159

https://bugzilla.suse.com/1070160

https://bugzilla.suse.com/1070163

https://bugzilla.suse.com/1074562

https://bugzilla.suse.com/1076116

https://bugzilla.suse.com/1076180

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0459-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here