Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2017:2611-1 Important: Xen DoS and Privilege Escalation Issues

suse
Calendar Grey October 2, 2017
Dist Suse Esm H88
Important notification regarding SUSE Xen resolution of serious vulnerabilities. Implement updates to ensure security compliance and operational stability.
An update that fixes three vulnerabilities is now available

Summary

This update for xen fixes several issues. These security issues were fixed: - CVE-2017-14316: Missing bound check in function `alloc_heap_pages` for an internal array allowed attackers using crafted hypercalls to execute arbitrary code within Xen (XSA-231, bsc#1056278) - CVE-2017-14317: A race in cxenstored may have cause a double-free allowind for DoS of the xenstored daemon (XSA-233, bsc#1056281). - CVE-2017-14319: An error while handling grant mappings allowed malicious or buggy x86 PV guest to escalate its privileges or crash the hypervisor (XSA-234, bsc#1056282). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-xen-13283=1

References

#1056278 #1056281 #1056282

Cross- CVE-2017-14316 CVE-2017-14317 CVE-2017-14319

Affected Products:

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2017-14316.html

https://www.suse.com/security/cve/CVE-2017-14317.html

https://www.suse.com/security/cve/CVE-2017-14319.html

https://bugzilla.suse.com/1056278

https://bugzilla.suse.com/1056281

https://bugzilla.suse.com/1056282

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2611-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here