Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: Xen Important Memory Access Issues Vuln 2026:0012-1

opensuse
Calendar Grey January 5, 2026
Dist Opensuse Esm H88
Update for openSUSE fixing six important vulnerabilities in Xen to enhance security and mitigate risks.
An update that solves six vulnerabilities can now be installed.

Description

This update for xen fixes the following issues:

Security issues fixed:

* CVE-2025-27466: NULL pointer dereference in the Viridian interface when

updating the reference TSC area (bsc#1248807).

* CVE-2025-58142: NULL pointer dereference in the Viridian interface due to

assumption that the SIM page is mapped when a synthetic timer message has to

be delivered (bsc#1248807).

* CVE-2025-58143: information leak and reference counter underflow in the

Viridian interface due to race in the mapping of the reference TSC page

(bsc#1248807).

* CVE-2025-58147: incorrect input sanitisation in Viridian hypercalls using

the HV_VP_SET Sparse format can lead to out-of-bounds write through

`vpmask_set()` (bsc#1251271).

* CVE-2025-58148: incorrect input sanitisation in Viridian hypercalls using

any input format can lead to out-of-bounds read through `send_ipi()`

(bsc#1251271).

* CVE-2025-58149: incorrect removal of permissions on PCI device unplug allows

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-12=1 openSUSE-SLE-15.6-2026-12=1

* Basesystem Module 15-SP6

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2026-12=1

* Server Applications Module 15-SP6

zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2026-12=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-12=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-12=1

Package List

* openSUSE Leap 15.6 (aarch64 x86_64 i586)

* xen-devel-4.18.5_08-150600.3.34.2

* xen-libs-debuginfo-4.18.5_08-150600.3.34.2

* xen-tools-domU-debuginfo-4.18.5_08-150600.3.34.2

* xen-tools-domU-4.18.5_08-150600.3.34.2

* xen-debugsource-4.18.5_08-150600.3.34.2

* xen-libs-4.18.5_08-150600.3.34.2

* openSUSE Leap 15.6 (x86_64)

* xen-libs-32bit-debuginfo-4.18.5_08-150600.3.34.2

* xen-libs-32bit-4.18.5_08-150600.3.34.2

* openSUSE Leap 15.6 (aarch64 x86_64)

* xen-4.18.5_08-150600.3.34.2

* xen-doc-html-4.18.5_08-150600.3.34.2

* xen-tools-debuginfo-4.18.5_08-150600.3.34.2

* xen-tools-4.18.5_08-150600.3.34.2

* openSUSE Leap 15.6 (noarch)

* xen-tools-xendomains-wait-disk-4.18.5_08-150600.3.34.2

* openSUSE Leap 15.6 (aarch64_ilp32)

* xen-libs-64bit-4.18.5_08-150600.3.34.2

* xen-libs-64bit-debuginfo-4.18.5_08-150600.3.34.2

* Basesystem Module 15-SP6 (x86_64)

* xen-libs-debuginfo-4.18.5_08-150600.3.34.2

* xen-tools-domU-debuginfo-4.18.5_08-150600.3.34.2

* xen-tools-domU-4.18.5_08-150600.3.34.2

*...

Read the Full Advisory

References

* bsc#1027519

* bsc#1248807

* bsc#1251271

* bsc#1252692

* bsc#1254180

## References:

* https://www.suse.com/security/cve/CVE-2025-27466.html

* https://www.suse.com/security/cve/CVE-2025-58142.html

* https://www.suse.com/security/cve/CVE-2025-58143.html

* https://www.suse.com/security/cve/CVE-2025-58147.html

* https://www.suse.com/security/cve/CVE-2025-58148.html

* https://www.suse.com/security/cve/CVE-2025-58149.html

* https://bugzilla.suse.com/show_bug.cgi?id=1027519

* https://bugzilla.suse.com/show_bug.cgi?id=1248807

* https://bugzilla.suse.com/show_bug.cgi?id=1251271

* https://bugzilla.suse.com/show_bug.cgi?id=1252692

* https://bugzilla.suse.com/show_bug.cgi?id=1254180

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0012-1
Release Date: 2026-01-05T10:31:33Z
Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here