Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2017:2864-1 Important: Xen Denial Of Service Risks

suse
Calendar Grey October 27, 2017
Dist Suse Esm H88
Updates to SUSE Linux Enterprise tackle several vulnerabilities in xen, implementing critical solutions for system robustness and protection against denial-of-service threats.
An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now...

Summary

This update for xen fixes several issues: These security issues were fixed: - CVE-2017-5526: The ES1370 audio device emulation support was vulnerable to a memory leakage issue allowing a privileged user inside the guest to cause a DoS and/or potentially crash the Qemu process on the host (bsc#1059777) - CVE-2017-15593: Missing cleanup in the page type system allowed a malicious or buggy PV guest to cause DoS (XSA-242 bsc#1061084) - CVE-2017-15592: A problem in the shadow pagetable code allowed a malicious or buggy HVM guest to cause DoS or cause hypervisor memory corruption potentially allowing the guest to escalate its privilege (XSA-243 bsc#1061086) - CVE-2017-15594: Problematic handling of the selector fields in the Interrupt Descriptor Table (IDT) allowed a malicious or buggy x86 PV

References

#1027519 #1057358 #1059777 #1061076 #1061077

#1061080 #1061081 #1061082 #1061084 #1061086

#1061087

Cross- CVE-2017-15588 CVE-2017-15589 CVE-2017-15590

CVE-2017-15591 CVE-2017-15592 CVE-2017-15593

CVE-2017-15594 CVE-2017-15595 CVE-2017-5526

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP2

SUSE Linux Enterprise Server 12-SP2

SUSE Linux Enterprise Desktop 12-SP2

SUSE Container as a Service Platform ALL

https://www.suse.com/security/cve/CVE-2017-15588.html

https://www.suse.com/security/cve/CVE-2017-15589.html

https://www.suse.com/security/cve/CVE-2017-15590.html

https://www.suse.com/security/cve/CVE-2017-15591.html

https://www.suse.com/security/cve/CVE-2017-15592.html

https://www.suse.com/security/cve/CVE-2017-15593.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:2864-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here