This update fixes the following security issues in xen: * CVE-2012-5510: Grant table version switch list corruption vulnerability (XSA-26) * CVE-2012-5511: Several HVM operations do not validate the range of their inputs (XSA-27) * CVE-2012-5512: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak (XSA-28) * CVE-2012-5513: XENMEM_exchange may overwrite hypervisor memory (XSA-29) * CVE-2012-5514: Missing unlock in guest_physmap_mark_populate_on_demand() (XSA-30) * CVE-2012-5515: Several memory hypercall operations allow invalid extent order values (XSA-31) Also the following bugs have been fixed and upstream patches have been applied: * FATAL PAGE FAULT in hypervisor (arch_do_domctl) * 25931-x86-domctl-iomem-mapping-checks.patch * 26132-tmem-save-NULL-check.patch
#777628 #789940 #789944 #789945 #789948 #789950
#789951 #789988 #792476
Cross- CVE-2012-5510 CVE-2012-5511 CVE-2012-5512
CVE-2012-5513 CVE-2012-5514 CVE-2012-5515
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2012-5510.html
https://www.suse.com/security/cve/CVE-2012-5511.html
https://www.suse.com/security/cve/CVE-2012-5512.html
https://www.suse.com/security/cve/CVE-2012-5513.html
https://www.suse.com/security/cve/CVE-2012-5514.html
https://www.suse.com/security/cve/CVE-2012-5515.html
Get the latest Linux and open source security news straight to your inbox.