Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE Linux Enterprise: 2020:1634-1 Important: Xen Security Update

suse
Calendar Grey June 17, 2020
Dist Suse Esm H88
Important Ubuntu Security Patch for kernel implements multiple corrections and significant flaws impacting corporate infrastructures.
An update that fixes 6 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2020-0543: Fixed a side channel attack against special registers which could have resulted in leaking of read values to cores other than the one which called it. This attack is known as Special Register Buffer Data Sampling (SRBDS) or "CrossTalk" (bsc#1172205). - CVE-2020-11742: Bad continuation handling in GNTTABOP_copy (bsc#1169392). - CVE-2020-11740, CVE-2020-11741: xen: XSA-313 multiple xenoprof issues (bsc#1168140). - CVE-2020-11739: Missing memory barriers in read-write unlock paths (bsc#1168142). - CVE-2020-11743: Bad error path in GNTTABOP_map_grant (bsc#1168143). - Xenstored Crashed during VM install (bsc#1167152) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1167152 #1168140 #1168142 #1168143 #1169392

#1172205

Cross- CVE-2020-0543 CVE-2020-11739 CVE-2020-11740

CVE-2020-11741 CVE-2020-11742 CVE-2020-11743

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-ESPOS

https://www.suse.com/security/cve/CVE-2020-0543.html

https://www.suse.com/security/cve/CVE-2020-11739.html

https://www.suse.com/security/cve/CVE-2020-11740.html

https://www.suse.com/security/cve/CVE-2020-11741.html

https://www.suse.com/security/cve/CVE-2020-11742.html

https://www.suse.com/security/cve/CVE-2020-11743.html

https://bugzilla.suse.com/1167152

https://bugzilla.suse.com/1168140

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1634-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here