Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2019:0825-1 Important: Xen Denial of Service Risks Fixed

suse
Calendar Grey April 1, 2019
Dist Suse Esm H88
SUSE has rolled out a crucial patch update for Xen, tackling numerous vulnerabilities with efficient remedies.
An update that solves 14 vulnerabilities and has 5 fixes is now available

Summary

This update for xen fixes the following issues: Security issues fixed: - CVE-2018-18849: Fixed an out of bounds memory access issue that was found in the LSI53C895A SCSI Host Bus Adapter emulation while writing a message in lsi_do_msgin. It could occur during migration if the 'msg_len' field has an invalid value. A user/process could use this flaw to crash the Qemu process resulting in DoS (bsc#1114423). - CVE-2018-19967: Fixed HLE constructs that allowed guests to lock up the host, resulting in a Denial of Service (DoS). (XSA-282) (bsc#1114988) - CVE-2018-19665: Fixed an integer overflow in Bluetooth routines allows memory corruption (bsc#1117756). - CVE-2018-18438: Fixed an integer overflow in ccid_card_vscard_read function which allows memory corruption (bsc#1112188).

References

#1056336 #1110924 #1111007 #1111011 #1111014

#1112188 #1114423 #1114988 #1115040 #1115047

#1117756 #1123157 #1126140 #1126141 #1126192

#1126195 #1126196 #1126201 #1129623

Cross- CVE-2017-13672 CVE-2018-10839 CVE-2018-17958

CVE-2018-17962 CVE-2018-17963 CVE-2018-18438

CVE-2018-18849 CVE-2018-19665 CVE-2018-19961

CVE-2018-19962 CVE-2018-19966 CVE-2018-19967

CVE-2019-6778 CVE-2019-9824

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

https://www.suse.com/security/cve/CVE-2017-13672.html

https://www.suse.com/security/cve/CVE-2018-10839.html

https://www.suse.com/security/cve/CVE-2018-17958.html

https://www.suse.com/security/cve/CVE-2018-17962.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0825-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here