Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2011:0983-1 Critical Security Alert: Xen Denial Of Service

suse
Calendar Grey September 1, 2011
Scroller Suse
SUSE Security Patch for Xen addresses severe denial of service vulnerabilities. Implement updates to maintain system integrity.
An update that fixes two vulnerabilities is now available

Summary

   SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID:    SUSE-SU-2011:0983-1
Rating:             important
References:         #712038 
Cross-References:   CVE-2011-2901 CVE-2011-3131
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4
                    SUSE Linux Enterprise Desktop 10 SP4
                    SLE SDK 10 SP4
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:


   This update fixes a denial of service (Host Crash) in the
   XEN hypervisor.  (CVE-2011-2901)

   Security Issue reference:

   * CVE-2011-2901
   
   * CVE-2011-3131
   

Indications:

   Please install this update.


Package List:

   - SUSE Linux Enterprise Server 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_37-0.9.1
      xen-devel-3.2.3_17040_37-0.9.1
      xen-doc-html-3.2.3_17040_37-0.9.1
      xen-doc-pdf-3.2.3_17040_37-0.9.1
      xen-doc-ps-3.2.3_17040_37-0.9.1
      xen-kmp-debug-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-default-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-kdump-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-smp-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-libs-3.2.3_17040_37-0.9.1
      xen-tools-3.2.3_17040_37-0.9.1
      xen-tools-domU-3.2.3_17040_37-0.9.1
      xen-tools-ioemu-3.2.3_17040_37-0.9.1

   - SUSE Linux Enterprise Server 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_37-0.9.1

   - SUSE Linux Enterprise Server 10 SP4 (i586):

      xen-kmp-bigsmp-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-kdumppae-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-vmi-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-vmipae-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_37-0.9.1
      xen-devel-3.2.3_17040_37-0.9.1
      xen-doc-html-3.2.3_17040_37-0.9.1
      xen-doc-pdf-3.2.3_17040_37-0.9.1
      xen-doc-ps-3.2.3_17040_37-0.9.1
      xen-kmp-default-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-smp-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-libs-3.2.3_17040_37-0.9.1
      xen-tools-3.2.3_17040_37-0.9.1
      xen-tools-domU-3.2.3_17040_37-0.9.1
      xen-tools-ioemu-3.2.3_17040_37-0.9.1

   - SUSE Linux Enterprise Desktop 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_37-0.9.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586):

      xen-kmp-bigsmp-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1

   - SLE SDK 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_37-0.9.1
      xen-devel-3.2.3_17040_37-0.9.1
      xen-kmp-debug-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-kmp-kdump-3.2.3_17040_37_2.6.16.60_0.89.2-0.9.1
      xen-libs-3.2.3_17040_37-0.9.1
      xen-tools-3.2.3_17040_37-0.9.1
      xen-tools-ioemu-3.2.3_17040_37-0.9.1

   - SLE SDK 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_37-0.9.1


References:

   https://www.suse.com/security/cve/CVE-2011-2901.html
   https://www.suse.com/security/cve/CVE-2011-3131.html
   
   

References

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.