Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:2787-1 Important: Xen Denial Of Service and Race Condition

suse
Calendar Grey September 29, 2020
Dist Suse Esm H88
SUSE has released a Security Update addressing various vulnerabilities in xen. It is crucial for systems to be updated promptly to reduce potential security threats.
An update that fixes 9 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2020-25604: Fixed a race condition when migrating timers between x86 HVM vCPU-s (bsc#1176343,XSA-336) - CVE-2020-25595: Fixed an issue where PCI passthrough code was reading back hardware registers (bsc#1176344,XSA-337) - CVE-2020-25597: Fixed an issue where a valid event channels may not turn invalid (bsc#1176346,XSA-338) - CVE-2020-25596: Fixed a potential denial of service in x86 pv guest kernel via SYSENTER (bsc#1176345,XSA-339) - CVE-2020-25603: Fixed an issue due to missing barriers when accessing/allocating an event channel (bsc#1176347,XSA-340) - CVE-2020-25600: Fixed out of bounds event channels available to 32-bit x86 domains (bsc#1176348,XSA-342) - CVE-2020-25599: Fixed race conditions with evtchn_reset() (bsc#1176349,XSA-343)

References

#1175534 #1176343 #1176344 #1176345 #1176346

#1176347 #1176348 #1176349 #1176350

Cross- CVE-2020-14364 CVE-2020-25595 CVE-2020-25596

CVE-2020-25597 CVE-2020-25599 CVE-2020-25600

CVE-2020-25601 CVE-2020-25603 CVE-2020-25604

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP3-BCL

SUSE Enterprise Storage 5

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2020-14364.html

https://www.suse.com/security/cve/CVE-2020-25595.html

https://www.suse.com/security/cve/CVE-2020-25596.html

https://www.suse.com/security/cve/CVE-2020-25597.html

https://www.suse.com/security/cve/CVE-2020-25599.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2787-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here