Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2021:1648-1 Important: Xen Critical Fix for DoS Attack

suse
Calendar Grey May 19, 2021
Scroller Suse
SUSE Security Patch for xen tackles a severe vulnerability and offers vital corrections, reinforcing overall system defenses.
An update that solves one vulnerability and has four fixes is now available

Summary

This update for xen fixes the following issues: Security issue fixed: - CVE-2021-28689: Fixed some x86 speculative vulnerabilities with bare (non-shim) 32-bit PV guests (XSA-370) (bsc#1185104) - Make sure xencommons is in a format as expected by fillup. (bsc#1185682) Each comment needs to be followed by an enabled key. Otherwise fillup will remove manually enabled key=value pairs, along with everything that looks like a stale comment, during next pkg update - A recent systemd update caused a regression in xenstored.service systemd now fails to track units that use systemd-notify (bsc#1183790) - Added a delay between the call to systemd-notify and the final exit of the wrapper script (bsc#1185021, bsc#1185196) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1183790 #1185021 #1185104 #1185196 #1185682

Cross- CVE-2021-28689

CVSS scores:

CVE-2021-28689 (SUSE): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud 9

SUSE Linux Enterprise Server for SAP 12-SP4

SUSE Linux Enterprise Server 12-SP4-LTSS

https://www.suse.com/security/cve/CVE-2021-28689.html

https://bugzilla.suse.com/1183790

https://bugzilla.suse.com/1185021

https://bugzilla.suse.com/1185104

https://bugzilla.suse.com/1185196

https://bugzilla.suse.com/1185682

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1648-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.