Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE: 2012:1487-1 Critical Update on Mitigation of Xen DoS Attacks

suse
Calendar Grey November 16, 2012
Dist Suse Esm H88
Updates for SUSE concerning Xen tackle significant vulnerabilities. Key security patches are now accessible for both users and administrators.
An update that fixes 8 vulnerabilities is now available

Summary

XEN received various security and bugfixes: * CVE-2012-4535: xen: Timer overflow DoS vulnerability (XSA-20) * CVE-2012-4537: xen: Memory mapping failure DoS vulnerability (XSA-22) The following additional bugs have beenfixed: * bnc#784087 - L3: Xen BUG at io_apic.c:129 26102-x86-IOAPIC-legacy-not-first.patch * Upstream patches from Jan 25927-x86-domctl-ioport-mapping-range.patch 25931-x86-domctl-iomem-mapping-checks.patch 26061-x86-oprof-counter-range.patch 25431-x86-EDD-MBR-sig-check.patch 25480-x86_64-sysret-canonical.patch 25481-x86_64-AMD-erratum-121.patch 25485-x86_64-canonical-checks.patch 25587-param-parse-limit.patch 25589-pygrub-size-limits.patch 25744-hypercall-return-long.patch 25765-x86_64-allow-unsafe-adjust.patch

References

#651093 #713555 #784087 #786516 #786517

Cross- CVE-2012-3497 CVE-2012-4411 CVE-2012-4535

CVE-2012-4536 CVE-2012-4537 CVE-2012-4538

CVE-2012-4539 CVE-2012-4544

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2012-3497.html

https://www.suse.com/security/cve/CVE-2012-4411.html

https://www.suse.com/security/cve/CVE-2012-4535.html

https://www.suse.com/security/cve/CVE-2012-4536.html

https://www.suse.com/security/cve/CVE-2012-4537.html

https://www.suse.com/security/cve/CVE-2012-4538.html

https://www.suse.com/security/cve/CVE-2012-4539.html

https://www.suse.com/security/cve/CVE-2012-4544.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:1487-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here