Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
This update for xen fixes the following issues:
* CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect
assertion (XSA-440) (bsc#1215744).
* CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with
IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746).
* CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443)
(bsc#1215747).
* CVE-2023-34327, CVE-2023-34328: Fixed multiple issues with AMD x86 debugging
functionality for guests (XSA-444) (bsc#1215748).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2023-4174=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4174=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4174=1
* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4174=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4174=1
* SUSE Manager Proxy 4.2
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4174=1
* SUSE Manager Retail Branch Server 4.2
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-
Server-4.2-2023-4174=1
* SUSE Manager Server 4.2
zypper in -t...
Read the Full Advisory* openSUSE Leap 15.3 (aarch64 x86_64 i586)
* xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1
* xen-libs-debuginfo-4.14.6_06-150300.3.57.1
* xen-tools-domU-4.14.6_06-150300.3.57.1
* xen-libs-4.14.6_06-150300.3.57.1
* xen-debugsource-4.14.6_06-150300.3.57.1
* xen-devel-4.14.6_06-150300.3.57.1
* openSUSE Leap 15.3 (x86_64)
* xen-libs-32bit-debuginfo-4.14.6_06-150300.3.57.1
* xen-libs-32bit-4.14.6_06-150300.3.57.1
* openSUSE Leap 15.3 (aarch64 x86_64)
* xen-4.14.6_06-150300.3.57.1
* xen-tools-debuginfo-4.14.6_06-150300.3.57.1
* xen-doc-html-4.14.6_06-150300.3.57.1
* xen-tools-4.14.6_06-150300.3.57.1
* openSUSE Leap 15.3 (noarch)
* xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1
* openSUSE Leap 15.3 (aarch64_ilp32)
* xen-libs-64bit-4.14.6_06-150300.3.57.1
* xen-libs-64bit-debuginfo-4.14.6_06-150300.3.57.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (x86_64)
* xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1
* xen-tools-debuginfo-4.14.6_06-150300.3.57.1
*...
Read the Full Advisory* bsc#1215744
* bsc#1215746
* bsc#1215747
* bsc#1215748
## References:
* https://www.suse.com/security/cve/CVE-2023-34323.html
* https://www.suse.com/security/cve/CVE-2023-34325.html
* https://www.suse.com/security/cve/CVE-2023-34326.html
* https://www.suse.com/security/cve/CVE-2023-34327.html
* https://www.suse.com/security/cve/CVE-2023-34328.html
* https://bugzilla.suse.com/show_bug.cgi?id=1215744
* https://bugzilla.suse.com/show_bug.cgi?id=1215746
* https://bugzilla.suse.com/show_bug.cgi?id=1215747
* https://bugzilla.suse.com/show_bug.cgi?id=1215748
Get the latest Linux and open source security news straight to your inbox.