Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

SUSE 12-SP2: 2021:3322-1 Moderate: Xen Security Issues Resolved

suse
Calendar Grey October 7, 2021
Scroller Suse
SUSE has released a security update addressing 13 vulnerabilities in xen, with several categorized as moderate. Users of Enterprise Server 12-SP2 are advised to apply this update.
An update that fixes 13 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2021-28701: Fixed race condition in XENMAPSPACE_grant_table handling (XSA-384) (bsc#1189632). - CVE-2021-28694,CVE-2021-28695,CVE-2021-28696: Fixed IOMMU page mapping issues on x86 (XSA-378)(bsc#1189373). - CVE-2021-28697: Fixed grant table v2 status pages that may remain accessible after de-allocation (XSA-379)(bsc#1189376). - CVE-2021-28698: Fixed long running loops in grant table handling (XSA-380)(bsc#1189378). - CVE-2021-20255: Fixed eepro100 stack overflow via infinite recursion (bsc#1182654). - CVE-2021-3592: Fixed invalid pointer initialization may lead to information disclosure (bootp) (bsc#1187369). - CVE-2021-3594: Fixed invalid pointer initialization may lead to information disclosure (udp) (bsc#1187378).

References

#1182654 #1186429 #1186433 #1186434 #1187369

#1187376 #1187378 #1189373 #1189376 #1189378

#1189632 #1189882

Cross- CVE-2021-0089 CVE-2021-20255 CVE-2021-28690

CVE-2021-28692 CVE-2021-28694 CVE-2021-28695

CVE-2021-28696 CVE-2021-28697 CVE-2021-28698

CVE-2021-28701 CVE-2021-3592 CVE-2021-3594

CVE-2021-3595

CVSS scores:

CVE-2021-0089 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CVE-2021-20255 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-20255 (SUSE): 3.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L

CVE-2021-28694 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-28695 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-28696 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Announcement ID: SUSE-SU-2021:3322-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.