Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:1138-1 Important Update For Xen Security Issues

suse
Calendar Grey April 29, 2020
Dist Suse Esm H88
SUSE has released an important patch for Xen that addresses several vulnerabilities and includes necessary repairs to enhance security and stability
An update that solves 6 vulnerabilities and has three fixes is now available

Summary

This update for xen fixes the following issues: Security issues fixed: - CVE-2020-11742: Bad continuation handling in GNTTABOP_copy (bsc#1169392). - CVE-2020-11740, CVE-2020-11741: xen: XSA-313 multiple xenoprof issues (bsc#1168140). - CVE-2020-11739: Missing memory barriers in read-write unlock paths (bsc#1168142). - CVE-2020-11743: Bad error path in GNTTABOP_map_grant (bsc#1168143). - CVE-2020-7211: Fixed potential directory traversal using relative paths via tftp server on Windows host (bsc#1161181). - arm: a CPU may speculate past the ERET instruction (bsc#1160932). Non-security issues fixed: - Xenstored Crashed during VM install (bsc#1167152) - DomU hang: soft lockup CPU #0 stuck under high load (bsc#1165206, bsc#1134506) - Update API compatibility versions, fixes issues for libvirt.

References

#1027519 #1155200 #1160932 #1161181 #1167152

#1168140 #1168142 #1168143 #1169392

Cross- CVE-2020-11739 CVE-2020-11740 CVE-2020-11741

CVE-2020-11742 CVE-2020-11743 CVE-2020-7211

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP4

https://www.suse.com/security/cve/CVE-2020-11739.html

https://www.suse.com/security/cve/CVE-2020-11740.html

https://www.suse.com/security/cve/CVE-2020-11741.html

https://www.suse.com/security/cve/CVE-2020-11742.html

https://www.suse.com/security/cve/CVE-2020-11743.html

https://www.suse.com/security/cve/CVE-2020-7211.html

https://bugzilla.suse.com/1027519

https://bugzilla.suse.com/1155200

https://bugzilla.suse.com/1160932

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1138-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here