Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

SUSE: 2022:0333-1 Important: Guest Mapping DoS Fixes for Xen

suse
Calendar Grey February 4, 2022
Scroller Suse
SUSE Security Update for kernel addresses significant memory handling and remote execution vulnerabilities. Restart system post-installation.
An update that fixes three vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2022-23033: Fixed guest_physmap_remove_page not removing the p2m mappings. (XSA-393) (bsc#1194576) - CVE-2022-23034: Fixed possible DoS by a PV guest Xen while unmapping a grant. (XSA-394) (bsc#1194581) - CVE-2022-23035: Fixed insufficient cleanup of passed-through device IRQs. (XSA-395) (bsc#1194588)

References

#1194576 #1194581 #1194588

Cross- CVE-2022-23033 CVE-2022-23034 CVE-2022-23035

CVSS scores:

CVE-2022-23034 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2022-23035 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP3

SUSE Linux Enterprise Server 15-SP3

SUSE Linux Enterprise Server for SAP Applications 15-SP3

SUSE Linux Enterprise High Performance Computing 15-SP3

SUSE Manager Server 4.2

SUSE Manager Proxy 4.2

SUSE Linux Enterprise Module for Basesystem 15-SP3

SUSE Linux Enterprise Server 15-SP3

SUSE Linux Enterprise Desktop 15-SP3

SUSE Linux Enterprise Server for SAP Applications 15-SP3

SUSE Linux Enterprise High Perfo...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0333-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.