Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE 11 SP2: 2013:1075-1 Important: Xen Denial Of Service Fixes

suse
Calendar Grey June 25, 2013
Dist Suse Esm H88
Essential patch for Xen on SUSE to address several vulnerabilities and improve security measures. Update promptly to safeguard your services!
An update that solves 10 vulnerabilities and has three An update that solves 10 vulnerabilities and has three An update that solves 10 vulnerabilities and has three fixes is now av...

Summary

XEN has been updated to 4.1.5 c/s 23509 to fix various bugs and security issues. The following security issues have been fixed: * CVE-2013-1918: Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier were not preemptible, which allowed local PV kernels to cause a denial of service via vectors related to deep page table traversal. * CVE-2013-1952: Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, did not properly check the source when accessing a bridge devices interrupt remapping table entries for MSI interrupts, which allowed local guest domains to cause a denial of service (interrupt injection) via unspecified vectors. * CVE-2013-2076: A information leak in the XSAVE/XRSTOR instructions could be used to determine state of floating point operations in other domains. *

References

#801663 #809662 #813673 #813675 #813677 #814709

#816156 #816159 #816163 #819416 #820917 #820919

#820920

Cross- CVE-2013-1917 CVE-2013-1918 CVE-2013-1919

CVE-2013-1920 CVE-2013-1952 CVE-2013-1964

CVE-2013-2072 CVE-2013-2076 CVE-2013-2077

CVE-2013-2078

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-1917.html

https://www.suse.com/security/cve/CVE-2013-1918.html

https://www.suse.com/security/cve/CVE-2013-1919.html

https://www.suse.com/security/cve/CVE-2013-1920.html

https://www.suse.com/security/cve/CVE-2013-1952.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:1075-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here