Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE 12-SP2: 2016:3208-1 Important: Xen Security Issues

suse
Calendar Grey December 21, 2016
Dist Suse Esm H88
Canonical has released important patches for Ubuntu, addressing significant vulnerabilities, thereby fortifying the security framework across various versions. Discover further details!
An update that fixes four vulnerabilities is now available

Summary

This update for xen fixes the following issues: - A Mishandling of SYSCALL singlestep during emulation which could have lead to privilege escalation. (XSA-204, bsc#1016340, CVE-2016-10013) - CMPXCHG8B emulation failed to ignore operand size override which could have lead to information disclosure. (XSA-200, bsc#1012651, CVE-2016-9932) - PV guests may have been able to mask interrupts causing a Denial of Service. (XSA-202, bsc#1014298, CVE-2016-10024) - A missing NULL pointer check in VMFUNC emulation could lead to a hypervisor crash leading to a Denial of Servce. (XSA-203, bsc#1014300, CVE-2016-10025) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP2:

References

#1012651 #1014298 #1014300 #1016340

Cross- CVE-2016-10013 CVE-2016-10024 CVE-2016-10025

CVE-2016-9932

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2016-10013.html

https://www.suse.com/security/cve/CVE-2016-10024.html

https://www.suse.com/security/cve/CVE-2016-10025.html

https://www.suse.com/security/cve/CVE-2016-9932.html

https://bugzilla.suse.com/1012651

https://bugzilla.suse.com/1014298

https://bugzilla.suse.com/1014300

https://bugzilla.suse.com/1016340

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3208-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here