Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE 11 SP3 Security Advisory: 2014:0373-1 Important Xen DoS Issues

suse
Calendar Grey March 14, 2014
Scroller Suse
Critical SUSE Xen security patch addresses several severe vulnerabilities impacting the overall security of the system.
An update that solves 12 vulnerabilities and has one errata An update that solves 12 vulnerabilities and has one errata An update that solves 12 vulnerabilities and has one errata ...

Summary

The SUSE Linux Enterprise Server 11 Service Pack 3 Xen hypervisor and toolset has been updated to 4.2.4 to fix various bugs and security issues: The following security issues have been addressed: * XSA-60: CVE-2013-2212: The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling chaches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range. (bnc#831120) * XSA-80: CVE-2013-6400: Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and allows local guest administrators to cause a denial of service (host crash) or gain privileges

References

#831120 #833251 #848014 #853048 #853049 #858311

#860092 #860163 #860165 #860300 #860302 #861256

#863297

Cross- CVE-2013-2212 CVE-2013-6400 CVE-2013-6885

CVE-2014-1642 CVE-2014-1666 CVE-2014-1891

CVE-2014-1892 CVE-2014-1893 CVE-2014-1894

CVE-2014-1895 CVE-2014-1896 CVE-2014-1950

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2013-2212.html

https://www.suse.com/security/cve/CVE-2013-6400.html

https://www.suse.com/security/cve/CVE-2013-6885.html

https://www.suse.com/security/cve/CVE-2014-1642.html

https://www.suse.com/security/cve/CVE-2014-1666.html

https://www.suse.com/security/cve/CVE-2014-1891.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0373-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.