Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2025:02290-1 moderate: xen indirect target selection security fix

suse
Calendar Grey July 11, 2025
Dist Suse Esm H88
The urgent deployment of essential updates addressing security flaws in Xen for SUSE Linux Enterprise Server 12 SP5 calls for immediate attention.
* bsc#1238043 * bsc#1243117 Cross-References: * CVE-2024-28956

Summary

## This update for xen fixes the following issues: * CVE-2024-28956: Fixed Intel CPU: Indirect Target Selection (ITS) (XSA-469) (bsc#1243117) * CVE-2025-1713: Fixed deadlock potential with VT-d and legacy PCI device pass-through (XSA-467) (bsc#1238043)

References

* bsc#1238043

* bsc#1243117

Cross-

* CVE-2024-28956

* CVE-2025-1713

CVSS scores:

* CVE-2024-28956 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2024-28956 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

* CVE-2024-28956 ( NVD ): 5.7

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2024-28956 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

* CVE-2025-1713 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

* CVE-2025-1713 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Enterprise Server 12 SP5

Announcement ID: SUSE-SU-2025:02290-1
Release Date: 2025-07-11T11:13:27Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here