Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2017:1081-1 Critical Update for Xen DoS and Memory Vulnerabilities

suse
Calendar Grey April 20, 2017
Dist Suse Esm H88
SUSE Security Advisory for xen addresses severe problems such as resource leaks, memory corruption, and denial of service vulnerabilities.
An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes An update that solves 5 vulnerabilities and has four fixes is ...

Summary

This update for xen fixes the following issues: These security issues were fixed: - CVE-2017-7228: Broken check in memory_exchange() permited PV guest breakout (bsc#1030442). - XSA-206: Unprivileged guests issuing writes to xenstore were able to stall progress of the control domain or driver domain, possibly leading to a Denial of Service (DoS) of the entire host (bsc#1030144). - CVE-2016-9603: A privileged user within the guest VM can cause a heap overflow in the device model process, potentially escalating their privileges to that of the device model process (bsc#1028655). - CVE-2017-6414: Memory leak in the vcard_apdu_new function in card_7816.c in libcacard allowed local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object (bsc#1027570).

References

#1022555 #1026636 #1027519 #1027570 #1028235

#1028655 #1029827 #1030144 #1030442

Cross- CVE-2016-9603 CVE-2017-2633 CVE-2017-6414

CVE-2017-6505 CVE-2017-7228

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-9603.html

https://www.suse.com/security/cve/CVE-2017-2633.html

https://www.suse.com/security/cve/CVE-2017-6414.html

https://www.suse.com/security/cve/CVE-2017-6505.html

https://www.suse.com/security/cve/CVE-2017-7228.html

https://bugzilla.suse.com/1022555

https://bugzilla.suse.com/1026636

https://bugzilla.suse.com/1027519

https://bugzilla.suse.com/1027570

https://bugzilla.suse.com/1028235

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1081-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here