Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

SUSE: 2017:1150-1 Important: Linux Kernel Security Patch

suse
Calendar Grey May 2, 2017
Scroller Suse
Essential patch for openSUSE correcting various vulnerabilities within xen, notably countering risks related to privilege elevation and denial-of-service exploits.
An update that solves four vulnerabilities and has three An update that solves four vulnerabilities and has three An update that solves four vulnerabilities and has three fixes is ...

Summary

This update for xen fixes several security issues: - A malicious 64-bit PV guest may be able to access all of system memory, allowing for all of privilege escalation, host crashes, and information leaks by placing a IRET hypercall in the middle of a multicall batch (XSA-213, bsc#1034843) - A malicious pair of guests may be able to access all of system memory, allowing for all of privilege escalation, host crashes, and information leaks because of a missing check when transfering pages via GNTTABOP_transfer (XSA-214, bsc#1034844). - CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions

References

#1028655 #1033948 #1034843 #1034844 #1034845

#1034994 #1035483

Cross- CVE-2016-9603 CVE-2017-7718 CVE-2017-7980

CVE-2017-7995

Affected Products:

SUSE OpenStack Cloud 5

SUSE Manager Proxy 2.1

SUSE Manager 2.1

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

https://www.suse.com/security/cve/CVE-2016-9603.html

https://www.suse.com/security/cve/CVE-2017-7718.html

https://www.suse.com/security/cve/CVE-2017-7980.html

https://www.suse.com/security/cve/CVE-2017-7995.html

https://bugzilla.suse.com/1028655

https://bugzilla.suse.com/1033948

https://bugzilla.suse.com/1034843

https://bugzilla.suse.com/1034844

https://bugzilla.suse.com/1034845

https://bugzilla.suse.com/1034994

https://bugzilla.suse.com/1035483

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1146-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.