Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE Linux 12-SP1: 2017:0570-1 Important: Xen DoS Risks

suse
Calendar Grey February 27, 2017
Dist Suse Esm H88
Patch addresses 13 critical flaws in xen to enhance security. Ensure your SUSE machine remains protected!
An update that solves 13 vulnerabilities and has three An update that solves 13 vulnerabilities and has three An update that solves 13 vulnerabilities and has three fixes is now av...

Summary

This update for xen fixes several issues. These security issues were fixed: - CVE-2017-5973: A infinite loop while doing control transfer in xhci_kick_epctx allowed privileged user inside the guest to crash the host process resulting in DoS (bsc#1025188). - CVE-2016-10155: The virtual hardware watchdog 'wdt_i6300esb' was vulnerable to a memory leakage issue allowing a privileged user to cause a DoS and/or potentially crash the Qemu process on the host (bsc#1024183). - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024834) - CVE-2017-5856: The MegaRAID SAS 8708EM2 Host Bus Adapter emulation

References

#1000195 #1002496 #1013657 #1013668 #1014490

#1014507 #1015169 #1016340 #1022627 #1022871

#1023004 #1024183 #1024186 #1024307 #1024834

#1025188

Cross- CVE-2016-10155 CVE-2016-9101 CVE-2016-9776

CVE-2016-9907 CVE-2016-9911 CVE-2016-9921

CVE-2016-9922 CVE-2017-2615 CVE-2017-2620

CVE-2017-5579 CVE-2017-5856 CVE-2017-5898

CVE-2017-5973

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP1

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2016-10155.html

https://www.suse.com/security/cve/CVE-2016-9101.html

https://www.suse.com/security/cve/CVE-2016-9776.html

https://www.suse.com/security/cve/CVE-2016-9907.html

https://www.suse.com/security/cve/CVE-2016-9911.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0570-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here