Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 11-SP4: 2016:3222-2 Critical Security Issue: Secure Boot Bypass

suse
Calendar Grey December 22, 2016
Dist Suse Esm H88
SUSE has released a critical security patch for xen, targeting various vulnerabilities. Ensure your systems remain secure by applying the latest updates.
An update that fixes three vulnerabilities is now available

Summary

This update for xen fixes the following issues: - A Mishandling of SYSCALL singlestep during emulation which could have lead to privilege escalation. (XSA-204, bsc#1016340, CVE-2016-10013) - CMPXCHG8B emulation failed to ignore operand size override which could have lead to information disclosure. (XSA-200, bsc#1012651, CVE-2016-9932) - PV guests may have been able to mask interrupts causing a Denial of Service. (XSA-202, bsc#1014298, CVE-2016-10024) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-xen-12905=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-xen-12905=1 - SUSE Linux Enterprise Debuginfo 11-SP4:

References

#1012651 #1014298 #1016340

Cross- CVE-2016-10013 CVE-2016-10024 CVE-2016-9932

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-10013.html

https://www.suse.com/security/cve/CVE-2016-10024.html

https://www.suse.com/security/cve/CVE-2016-9932.html

https://bugzilla.suse.com/1012651

https://bugzilla.suse.com/1014298

https://bugzilla.suse.com/1016340

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:3221-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here