Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: SUSE-SU-2021:3842-1 Moderate: Xen Security Update

suse
Calendar Grey December 1, 2021
Dist Suse Esm H88
An urgent security alert for Xen on SUSE Linux highlights several weaknesses requiring attention to enhance overall system integrity.
An update that fixes 7 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2021-28701: Fixed race condition in XENMAPSPACE_grant_table handling (XSA-384) (bsc#1189632). - CVE-2021-28704, CVE-2021-28707, CVE-2021-28708: Fixed PoD operations on misaligned GFNs (XSA-388) (bsc#1192557). - CVE-2021-28705, CVE-2021-28709: Fixed issues with partially successful P2M updates on x86 (XSA-389) (bsc#1192559). - CVE-2021-28706: Fixed guests may exceed their designated memory limit (XSA-385) (bsc#1192554). - Integrate bugfixes (bsc#1189373, bsc#1189378).

References

#1189373 #1189378 #1189632 #1192554 #1192557

#1192559

Cross- CVE-2021-28701 CVE-2021-28704 CVE-2021-28705

CVE-2021-28706 CVE-2021-28707 CVE-2021-28708

CVE-2021-28709

CVSS scores:

CVE-2021-28701 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-28704 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-28705 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-28706 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CVE-2021-28706 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-28707 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-28708 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Announcement ID: SUSE-SU-2021:3842-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here