Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE Linux Enterprise: 2025:01703-1 moderate: xen CPU Threat Fix

suse
Calendar Grey May 26, 2025
Dist Suse Esm H88
Critical SUSE security patch for xen resolving an Intel processor vulnerability along with additional corrections. System restart necessary after installation.
* bsc#1027519 * bsc#1242490 * bsc#1243117 Cross-References:

Summary

## This update for xen fixes the following issues: Update to Xen 4.18.5: Security fixes: * CVE-2024-28956: Fixed Intel CPU Indirect Target Selection (ITS) (bsc#1243117) Other fixes: * Fixed boot failing with XEN kernel on DL580 Gen12 (bsc#1242490) * Added missing upstream bug fixes (bsc#1027519)

References

* bsc#1027519

* bsc#1242490

* bsc#1243117

Cross-

* CVE-2024-28956

CVSS scores:

* CVE-2024-28956 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2024-28956 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

* CVE-2024-28956 ( NVD ): 5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2024-28956 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products:

* Basesystem Module 15-SP6

* openSUSE Leap 15.6

* Server Applications Module 15-SP6

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP6

Announcement ID: SUSE-SU-2025:01703-1
Release Date: 2025-05-25T21:42:32Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here