Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:0334-1 Important: Xen Security Update for DoS Issues

suse
Calendar Grey February 6, 2020
Dist Suse Esm H88
Important SUSE Security Patch: Addresses various vulnerabilities in xen that affect SUSE Linux Enterprise platforms.
An update that fixes 13 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2020-7211: potential directory traversal using relative paths via tftp server on Windows host (bsc#1161181). - CVE-2019-19579: Device quarantine for alternate pci assignment methods (bsc#1157888). - CVE-2019-19581: find_next_bit() issues (bsc#1158003). - CVE-2019-19583: VMentry failure with debug exceptions and blocked states (bsc#1158004). - CVE-2019-19578: Linear pagetable use / entry miscounts (bsc#1158005). - CVE-2019-19580: Further issues with restartable PV type change operations (bsc#1158006). - CVE-2019-19577: dynamic height for the IOMMU pagetables (bsc#1158007). - CVE-2019-18420: VCPUOP_initialise DoS (bsc#1154448). - CVE-2019-18425: missing descriptor table limit checking in x86 PV emulation (bsc#1154456).

References

#1152497 #1154448 #1154456 #1154458 #1154461

#1155945 #1157888 #1158003 #1158004 #1158005

#1158006 #1158007 #1161181

Cross- CVE-2018-12207 CVE-2019-11135 CVE-2019-18420

CVE-2019-18421 CVE-2019-18424 CVE-2019-18425

CVE-2019-19577 CVE-2019-19578 CVE-2019-19579

CVE-2019-19580 CVE-2019-19581 CVE-2019-19583

CVE-2020-7211

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2018-12207.html

https://www.suse.com/security/cve/CVE-2019-11135.html

https://www.suse.com/security/cve/CVE-2019-18420.html

https://www.suse.com/security/cve/CVE-2019-18421.html

https://www.suse.com/security/cve/CVE-2019-18424.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0334-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here