Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2024:3423-1 important: xen updates for critical issues

suse
Calendar Grey September 24, 2024
Dist Suse Esm H88
SUSE releases new patches for xen to mitigate severe security vulnerabilities. Keep updated about essential corrections and the potential impact on your infrastructure.
* bsc#1222453 * bsc#1227355 * bsc#1228574 * bsc#1228575 * bsc#1230366

Summary

## This update for xen fixes the following issues: * CVE-2024-2201: Mitigation for Native Branch History Injection (XSA-456, bsc#1222453) * CVE-2024-31143: Fixed double unlock in x86 guest IRQ handling (XSA-458, bsc#1227355) * CVE-2024-31145: Fixed error handling in x86 IOMMU identity mapping (XSA-460, bsc#1228574) * CVE-2024-31146: Fixed PCI device pass-through with shared resources (XSA-461, bsc#1228575) * CVE-2024-45817: Fixed a deadlock in vlapic_error (XSA-462, bsc#1230366)

References

* bsc#1222453

* bsc#1227355

* bsc#1228574

* bsc#1228575

* bsc#1230366

Cross-

* CVE-2024-2201

* CVE-2024-31143

* CVE-2024-31145

* CVE-2024-31146

* CVE-2024-45817

CVSS scores:

* CVE-2024-2201 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2024-31143 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-31145 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

* CVE-2024-31146 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N

* CVE-2024-45817 ( SUSE ): 6.9

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-45817 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4

* SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3423-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here