Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE Linux 12-SP2 SUSE-SU-2017:0571-1 Important: DoS Risk in Xen

suse
Calendar Grey February 27, 2017
Dist Suse Esm H88
Crucial SUSE update for Xen resolves various problems. Here are the specifics regarding security flaws and their remedies.
An update that solves four vulnerabilities and has 7 fixes An update that solves four vulnerabilities and has 7 fixes An update that solves four vulnerabilities and has 7 fixes is ...

Summary

This update for xen fixes several issues. These security issues were fixed: - CVE-2017-2620: In CIRRUS_BLTMODE_MEMSYSSRC mode the bitblit copy routine cirrus_bitblt_cputovideo failed to check the memory region, allowing for an out-of-bounds write that allows for privilege escalation (bsc#1024834). - CVE-2017-2615: An error in the bitblt copy operation could have allowed a malicious guest administrator to cause an out of bounds memory access, possibly leading to information disclosure or privilege escalation (bsc#1023004). - A malicious guest could have, by frequently rebooting over extended periods of time, run the host system out of memory, resulting in a Denial of Service (DoS) (bsc#1022871) - CVE-2016-9921: The Cirrus CLGD 54xx VGA Emulator support was vulnerable

References

#1000195 #1002496 #1005028 #1012651 #1014298

#1014300 #1015169 #1016340 #1022871 #1023004

#1024834

Cross- CVE-2016-9921 CVE-2016-9922 CVE-2017-2615

CVE-2017-2620

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

https://www.suse.com/security/cve/CVE-2016-9921.html

https://www.suse.com/security/cve/CVE-2016-9922.html

https://www.suse.com/security/cve/CVE-2017-2615.html

https://www.suse.com/security/cve/CVE-2017-2620.html

https://bugzilla.suse.com/1000195

https://bugzilla.suse.com/1002496

https://bugzilla.suse.com/1005028

https://bugzilla.suse.com/1012651

https://bugzilla.suse.com/1014298

https://bugzilla.suse.com/1014300

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:0571-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here