Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE Linux 12-SP1: 2021:1234-5 Major: 12 Essential Kernel Updates

suse
Calendar Grey October 12, 2016
Dist Suse Esm H88
Update addresses 10 essential concerns in Xen for SUSE, implementing various corrections. Key improvements for safeguarding system security and maintaining integrity.
An update that solves 10 vulnerabilities and has 8 fixes is An update that solves 10 vulnerabilities and has 8 fixes is An update that solves 10 vulnerabilities and has 8 fixes is ...

Summary

This update for xen fixes several issues. These security issues were fixed: - CVE-2016-7092: The get_page_from_l3e function in arch/x86/mm.c in Xen allowed local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables (bsc#995785) - CVE-2016-7093: Xen allowed local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation (bsc#995789) - CVE-2016-7094: Buffer overflow in Xen allowed local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update (bsc#995792) - CVE-2016-7154: Use-after-free vulnerability in the FIFO event channel

References

#966467 #970135 #971949 #988675 #990970 #991934

#992224 #993507 #994136 #994421 #994625 #994761

#994772 #994775 #995785 #995789 #995792 #997731

Cross- CVE-2016-6258 CVE-2016-6833 CVE-2016-6834

CVE-2016-6835 CVE-2016-6836 CVE-2016-6888

CVE-2016-7092 CVE-2016-7093 CVE-2016-7094

CVE-2016-7154

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-6258.html

https://www.suse.com/security/cve/CVE-2016-6833.html

https://www.suse.com/security/cve/CVE-2016-6834.html

https://www.suse.com/security/cve/CVE-2016-6835.html

https://www.suse.com/security/cve/CVE-2016-6836.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2507-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here