Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Enterprise Server 12 SP5: 2024:1541-1 Moderate: Xen Threats

suse
Calendar Grey May 7, 2024
Dist Suse Esm H88
SUSE has issued a significant security patch for xen, tackling several vulnerabilities with critical remedies and guidelines provided.
* bsc#1027519 * bsc#1221984 * bsc#1222302 * bsc#1222453

Summary

## This update for xen fixes the following issues: * CVE-2024-2201: Mitigation for Native Branch History Injection (XSA-456, bsc#1222453) * CVE-2023-46842: HVM hypercalls may trigger Xen bug check (XSA-454, bsc#1221984) * CVE-2024-31142: Fixed incorrect logic for BTC/SRSO mitigations (XSA-455, bsc#1222302) * Upstream bug fixes (bsc#1027519)

References

* bsc#1027519

* bsc#1221984

* bsc#1222302

* bsc#1222453

Cross-

* CVE-2023-46842

* CVE-2024-2201

* CVE-2024-31142

CVSS scores:

* CVE-2023-46842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

* CVE-2024-2201 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2024-31142 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

An update that solves three vulnerabilities and has one security fix can now be

installed.

##

* https://www.suse.com/security/cve/CVE-2023-46842.html

* https://www.suse.com/security/cve/CVE-2024-2201.html

Announcement ID: SUSE-SU-2024:1541-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here