Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE Update 2024:3980-1 moderate: xen Deadlocks and Data Leak Fix

suse
Calendar Grey November 12, 2024
Dist Suse Esm H88
This critical security patch for Xen in SUSE addresses deadlock issues and data exposure risks. Follow the listed steps for a secure update
* bsc#1027519 * bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

Summary

## This update for xen fixes the following issues: Security issues fixed: * CVE-2024-45818: xen: Deadlock in x86 HVM standard VGA handling (bsc#1232622) * CVE-2024-45819: xen: libxl leaks data to PVH guests via ACPI tables (bsc#1232624) * CVE-2024-45817: xen: x86: Deadlock in vlapic_error() (bsc#1230366) Non-security issues fixed: * Removed usage of net-tools-deprecated from supportconfig plugin (bsc#1232542) * Upstream bug fixes (bsc#1027519)

References

* bsc#1027519

* bsc#1230366

* bsc#1232542

* bsc#1232622

* bsc#1232624

Cross-

* CVE-2024-45817

* CVE-2024-45818

* CVE-2024-45819

CVSS scores:

* CVE-2024-45817 ( SUSE ): 6.9

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-45817 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-45818 ( SUSE ): 8.2

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

* CVE-2024-45818 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

* CVE-2024-45819 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

* CVE-2024-45819 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products:

* Basesystem Module 15-SP5

* openSUSE Leap 15.5

* openSUSE Leap Micro 5.5

Announcement ID: SUSE-SU-2024:3980-1
Release Date: 2024-11-12T16:14:14Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here