Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE 15.3: 2023:4174-1 Important: Xen Crash Issues Fix

opensuse
Calendar Grey October 24, 2023
Dist Opensuse Esm H88
Urgent advisory for openSUSE regarding significant vulnerabilities in xen that could lead to system instability and various parsing failures. Ensure you update immediately.
This update for xen fixes the following issues: CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744).

Description

This update for xen fixes the following issues:

* CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect

assertion (XSA-440) (bsc#1215744).

* CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with

IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746).

* CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443)

(bsc#1215747).

* CVE-2023-34327, CVE-2023-34328: Fixed multiple issues with AMD x86 debugging

functionality for guests (XSA-444) (bsc#1215748).

## Special Instructions and Notes:

* Please reboot the system after installing this update.

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.3

zypper in -t patch SUSE-2023-4174=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4174=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4174=1

* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3

zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4174=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP3

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4174=1

* SUSE Manager Proxy 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4174=1

* SUSE Manager Retail Branch Server 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-

Server-4.2-2023-4174=1

* SUSE Manager Server 4.2

zypper in -t...

Read the Full Advisory

Package List

* openSUSE Leap 15.3 (aarch64 x86_64 i586)

* xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1

* xen-libs-debuginfo-4.14.6_06-150300.3.57.1

* xen-tools-domU-4.14.6_06-150300.3.57.1

* xen-libs-4.14.6_06-150300.3.57.1

* xen-debugsource-4.14.6_06-150300.3.57.1

* xen-devel-4.14.6_06-150300.3.57.1

* openSUSE Leap 15.3 (x86_64)

* xen-libs-32bit-debuginfo-4.14.6_06-150300.3.57.1

* xen-libs-32bit-4.14.6_06-150300.3.57.1

* openSUSE Leap 15.3 (aarch64 x86_64)

* xen-4.14.6_06-150300.3.57.1

* xen-tools-debuginfo-4.14.6_06-150300.3.57.1

* xen-doc-html-4.14.6_06-150300.3.57.1

* xen-tools-4.14.6_06-150300.3.57.1

* openSUSE Leap 15.3 (noarch)

* xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1

* openSUSE Leap 15.3 (aarch64_ilp32)

* xen-libs-64bit-4.14.6_06-150300.3.57.1

* xen-libs-64bit-debuginfo-4.14.6_06-150300.3.57.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (x86_64)

* xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1

* xen-tools-debuginfo-4.14.6_06-150300.3.57.1

*...

Read the Full Advisory

References

* bsc#1215744

* bsc#1215746

* bsc#1215747

* bsc#1215748

## References:

* https://www.suse.com/security/cve/CVE-2023-34323.html

* https://www.suse.com/security/cve/CVE-2023-34325.html

* https://www.suse.com/security/cve/CVE-2023-34326.html

* https://www.suse.com/security/cve/CVE-2023-34327.html

* https://www.suse.com/security/cve/CVE-2023-34328.html

* https://bugzilla.suse.com/show_bug.cgi?id=1215744

* https://bugzilla.suse.com/show_bug.cgi?id=1215746

* https://bugzilla.suse.com/show_bug.cgi?id=1215747

* https://bugzilla.suse.com/show_bug.cgi?id=1215748

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4174-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here