This update for xen fixes the following issues: - CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806). - CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807). - CVE-2021-28689: Fixed speculative vulnerabilities with bare (non-shim) 32-bit PV guests (bsc#1185104). - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488)
#1185104 #1193923 #1199966 #1200762 #1203806
#1203807 #1204482 #1204485 #1204487 #1204488
#1204489 #1204490 #1204494 #1204496
Cross- CVE-2021-28689 CVE-2022-26365 CVE-2022-33740
CVE-2022-33741 CVE-2022-33742 CVE-2022-33746
CVE-2022-33748 CVE-2022-42309 CVE-2022-42310
CVE-2022-42311 CVE-2022-42312 CVE-2022-42313
CVE-2022-42314 CVE-2022-42315 CVE-2022-42316
CVE-2022-42317 CVE-2022-42318 CVE-2022-42319
CVE-2022-42320 CVE-2022-42321 CVE-2022-42322
CVE-2022-42323 CVE-2022-42325 CVE-2022-42326
CVSS scores:
CVE-2021-28689 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2021-28689 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2022-26365 (NVD) : 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Get the latest Linux and open source security news straight to your inbox.