Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2015:1908-2 Critical: Xen Remote Access Vulnerabilities Corrections

suse
Calendar Grey November 4, 2015
Dist Suse Esm H88
SUSE issues critical patch for KVM, resolving 7 security flaws and ensuring essential updates for reliable performance.
An update that solves 8 vulnerabilities and has 8 fixes is An update that solves 8 vulnerabilities and has 8 fixes is An update that solves 8 vulnerabilities and has 8 fixes is now...

Summary

xen was updated to version 4.4.3 to fix nine security issues. These security issues were fixed: - CVE-2015-4037: The slirp_smb function in net/slirp.c created temporary files with predictable names, which allowed local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program (bsc#932267). - CVE-2014-0222: Integer overflow in the qcow_open function allowed remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image (bsc#877642). - CVE-2015-7835: Uncontrolled creation of large page mappings by PV guests (bsc#950367). - CVE-2015-7311: libxl in Xen did not properly handle the readonly flag on disks when using the qemu-xen device model, which allowed local guest users to write to a read-only disk image (bsc#947165).

References

#877642 #901488 #907514 #910258 #918984 #923967

#932267 #944463 #944697 #945167 #947165 #949138

#950367 #950703 #950705 #950706

Cross- CVE-2014-0222 CVE-2015-4037 CVE-2015-5239

CVE-2015-6815 CVE-2015-7311 CVE-2015-7835

CVE-2015-7969 CVE-2015-7971

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2015-4037.html

https://www.suse.com/security/cve/CVE-2015-5239.html

https://www.suse.com/security/cve/CVE-2015-6815.html

https://www.suse.com/security/cve/CVE-2015-7311.html

https://www.suse.com/security/cve/CVE-2015-7835.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1908-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here