Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE 2020:0388-1 Important: Xen Security Update for Multiple Issues

suse
Calendar Grey February 17, 2020
Dist Suse Esm H88
The latest patch addresses critical vulnerabilities in xen, including several necessary corrections. Suggested procedures for installation are outlined.
An update that fixes 25 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2018-12207: Fixed a race condition where untrusted virtual machines could have been using the Instruction Fetch Unit of the Intel CPU to cause a Machine Exception during Page Size Change, causing the CPU core to be non-functional (bsc#1155945 XSA-304). - CVE-2018-19965: Fixed a DoS from attempting to use INVPCID with a non-canonical addresses (bsc#1115045 XSA-279). - CVE-2019-11135: Aborting an asynchronous TSX operation on Intel CPUs with Transactional Memory support could be used to facilitate side-channel information leaks out of microarchitectural buffers, similar to the previously described "Microarchitectural Data Sampling" attack. (bsc#1152497 XSA-305). - CVE-2019-12067: Fixed a null pointer dereference in QEMU AHCI (bsc#1145652).

References

#1115045 #1126140 #1126141 #1126192 #1126195

#1126196 #1126201 #1135905 #1143797 #1145652

#1146874 #1149813 #1152497 #1154448 #1154456

#1154458 #1154461 #1155945 #1157888 #1158003

#1158004 #1158005 #1158006 #1158007 #1161181

Cross- CVE-2018-12207 CVE-2018-19965 CVE-2019-11135

CVE-2019-12067 CVE-2019-12068 CVE-2019-12155

CVE-2019-14378 CVE-2019-15890 CVE-2019-17340

CVE-2019-17341 CVE-2019-17342 CVE-2019-17343

CVE-2019-17344 CVE-2019-17347 CVE-2019-18420

CVE-2019-18421 CVE-2019-18424 CVE-2019-18425

CVE-2019-19577 CVE-2019-19578 CVE-2019-19579

CVE-2019-19580 CVE-2019-19581 CVE-2019-19583

CVE-2020-7211

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0388-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here