Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

SUSE: 2017:2751-1 Important: Xen DoS Crash and Memory Leak

suse
Calendar Grey October 17, 2017
Dist Suse Esm H88
Tackling essential challenges in SUSE Xen through required updates and patches for improved security and overall system reliability.
An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is An update that solves one vulnerability and has 10 fixes is ...

Summary

This update for xen fixes several issues: These security issues were fixed: - CVE-2017-5526: The ES1370 audio device emulation support was vulnerable to a memory leakage issue allowing a privileged user inside the guest to cause a DoS and/or potentially crash the Qemu process on the host (bsc#1059777) - bsc#1061084: Missing cleanup in the page type system allowed a malicious or buggy PV guest to cause DoS (XSA-242) - bsc#1061086: A problem in the shadow pagetable code allowed a malicious or buggy HVM guest to cause DoS or cause hypervisor memory corruption potentially allowing the guest to escalate its privilege (XSA-243) - bsc#1061087: Problematic handling of the selector fields in the Interrupt Descriptor Table (IDT) allowed a malicious or buggy x86 PV guest to escalate its privileges or cause DoS (XSA-244)

References

#1027519 #1055321 #1059777 #1061076 #1061077

#1061080 #1061081 #1061082 #1061084 #1061086

#1061087

Cross- CVE-2017-5526

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2017-5526.html

https://bugzilla.suse.com/1027519

https://bugzilla.suse.com/1055321

https://bugzilla.suse.com/1059777

https://bugzilla.suse.com/1061076

https://bugzilla.suse.com/1061077

https://bugzilla.suse.com/1061080

https://bugzilla.suse.com/1061081

https://bugzilla.suse.com/1061082

https://bugzilla.suse.com/1061084

https://bugzilla.suse.com/1061086

https://bugzilla.suse.com/1061087

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2751-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here