This update for xen fixes the following issues:
Update to Xen 4.13.3 general bug fix release (bsc#1027519).
Security issues fixed:
- CVE-2021-28693: xen/arm: Boot modules are not scrubbed (bsc#1186428)
- CVE-2021-28692: xen: inappropriate x86 IOMMU timeout detection /
handling (bsc#1186429)
- CVE-2021-0089: xen: Speculative Code Store Bypass (bsc#1186433)
- CVE-2021-28690: xen: x86: TSX Async Abort protections not restored after
S3 (bsc#1186434)
- CVE-2021-28694,CVE-2021-28695,CVE-2021-28696: IOMMU page mapping issues
on x86 (XSA-378)(bsc#1189373).
- CVE-2021-28697: grant table v2 status pages may remain accessible after
de-allocation (XSA-379)(bsc#1189376).
- CVE-2021-28698: long running loops in grant table handling
(XSA-380)(bsc#1189378).
- CVE-2021-28699: inadequate grant-v2 status frames array bounds check
(XSA-382)(bsc#1189380).
- CVE-2021-28700: No memory limit for dom0less domUs
(XSA-383)(bsc#1189381).
Read the Full Advisory
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-1236=1
- openSUSE Leap 15.2 (i586 x86_64):
xen-debugsource-4.13.3_02-lp152.2.27.1
xen-devel-4.13.3_02-lp152.2.27.1
xen-libs-4.13.3_02-lp152.2.27.1
xen-libs-debuginfo-4.13.3_02-lp152.2.27.1
xen-tools-domU-4.13.3_02-lp152.2.27.1
xen-tools-domU-debuginfo-4.13.3_02-lp152.2.27.1
- openSUSE Leap 15.2 (noarch):
xen-tools-xendomains-wait-disk-4.13.3_02-lp152.2.27.1
- openSUSE Leap 15.2 (x86_64):
xen-4.13.3_02-lp152.2.27.1
xen-doc-html-4.13.3_02-lp152.2.27.1
xen-libs-32bit-4.13.3_02-lp152.2.27.1
xen-libs-32bit-debuginfo-4.13.3_02-lp152.2.27.1
xen-tools-4.13.3_02-lp152.2.27.1
xen-tools-debuginfo-4.13.3_02-lp152.2.27.1
https://www.suse.com/security/cve/CVE-2021-0089.html
https://www.suse.com/security/cve/CVE-2021-28690.html
https://www.suse.com/security/cve/CVE-2021-28692.html
https://www.suse.com/security/cve/CVE-2021-28693.html
https://www.suse.com/security/cve/CVE-2021-28694.html
https://www.suse.com/security/cve/CVE-2021-28695.html
https://www.suse.com/security/cve/CVE-2021-28696.html
https://www.suse.com/security/cve/CVE-2021-28697.html
https://www.suse.com/security/cve/CVE-2021-28698.html
https://www.suse.com/security/cve/CVE-2021-28699.html
https://www.suse.com/security/cve/CVE-2021-28700.html
https://bugzilla.suse.com/1027519
https://bugzilla.suse.com/1137251
https://bugzilla.suse.com/1176189
https://bugzilla.suse.com/1179148
https://bugzilla.suse.com/1179246
https://bugzilla.suse.com/1180491
https://bugzilla.suse.com/1181989
https://bugzilla.suse.com/1183877
https://bugzilla.suse.com/1185682
https://bugzilla.suse.com/1186428
https://bugzilla.suse.com/1186429
https://bugzilla.suse.com/1186433
https://bugzilla.suse....
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.