x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841) x86: Register File Data Sampling. (CVE-2023-28746) GhostRace: Speculative Race Conditions. (CVE-2024-2193) References: . MGASA-2024-0115 - Updated xen packages fix security vulnerabilities Publication date: 10 Apr 2024 URL: https://advisories.mageia.org/MGASA-2024-0115.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-46841, CVE-2023-28746, CVE-2024-2193 x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841) x86: Register File Data Sampling. (CVE-2023-28746) GhostRace: Speculative Race Conditions. (CVE-2024-2193) References: - https://bugs.mageia.org/show_bug.cgi?id=32905 - https://www.openwall.com/lists/oss-security/2024/02/27/2 - https://www.openwall.com/lists/oss-security/2024/03/12/13 - https://www.openwall.com/lists/oss-security/2024/03/12/14 - https://www.cve.org/CVERecord?id=CVE-2023-46841 - https://www.cve.org/CVERecord?id=CVE-2023-28746 - https://www.cve.org/CVERecord?id=CVE-2024-2193 SRPMS: - 9/core/xen-4.17.3-1.1.mga9 . Enhanced xen packages released to resolve significant security vulnerabilities in Mageia 9. Announcement date is April 10, 2024. Further information included.. Mageia Security Update, Xen Critical Advisory, Security Patch Mageia. . Severity: Critical. LinuxSecurity.com Team
* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 . # Security update for xen Announcement ID: SUSE-SU-2024:1101-1 Rating: moderate References: * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1101=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1101=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1101=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1101=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1101=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1101=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1101=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64 i586) * xen-libs-4.16.5_14-150400.4.52.1 * xen-tools-domU-4.16.5_14-150400.4.52.1 * xen-tools-domU-debuginfo-4.16.5_14-150400.4.52.1 *xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-devel-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (x86_64) * xen-libs-32bit-4.16.5_14-150400.4.52.1 * xen-libs-32bit-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (aarch64 x86_64) * xen-doc-html-4.16.5_14-150400.4.52.1 * xen-4.16.5_14-150400.4.52.1 * xen-tools-4.16.5_14-150400.4.52.1 * xen-tools-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (aarch64_ilp32) * xen-libs-64bit-4.16.5_14-150400.4.52.1 * xen-libs-64bit-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap Micro 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap Micro 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . A new securityenhancement for Xen from SUSE resolves existing vulnerabilities of moderate impact and includes guidance for applying the necessary updates.. openSUSE Xen Fix, Race Conditions Patch, Data Sampling Update. . LinuxSecurity.com Team
This update for xen fixes the following issues: CVE-2023-28746: Register File Data Sampling (bsc#1221332) CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334). # Security update for xen Announcement ID: SUSE-SU-2024:1101-1 Rating: moderate References: * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1101=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1101=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1101=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1101=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1101=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1101=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1101=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64 i586) *xen-libs-4.16.5_14-150400.4.52.1 * xen-tools-domU-4.16.5_14-150400.4.52.1 * xen-tools-domU-debuginfo-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-devel-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (x86_64) * xen-libs-32bit-4.16.5_14-150400.4.52.1 * xen-libs-32bit-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (aarch64 x86_64) * xen-doc-html-4.16.5_14-150400.4.52.1 * xen-4.16.5_14-150400.4.52.1 * xen-tools-4.16.5_14-150400.4.52.1 * xen-tools-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.5_14-150400.4.52.1 * openSUSE Leap 15.4 (aarch64_ilp32) * xen-libs-64bit-4.16.5_14-150400.4.52.1 * xen-libs-64bit-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap Micro 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * openSUSE Leap Micro 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-libs-4.16.5_14-150400.4.52.1 * xen-debugsource-4.16.5_14-150400.4.52.1 * xen-libs-debuginfo-4.16.5_14-150400.4.52.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html *https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . Patch released to address CVE-2023-28746 and CVE-2024-2193 vulnerabilities in xen, classified with a moderate severity level; comprehensive guidance for applying the updates included.. openSUSE Security Update, Xen Race Condition, Data Sampling Fix. . LinuxSecurity.com Team
This update for xen fixes the following issues: CVE-2023-28746: Register File Data Sampling (bsc#1221332) CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334). # Security update for xen Announcement ID: SUSE-SU-2024:1102-1 Rating: moderate References: * bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2023-46841 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2023-46841 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) * CVE-2023-46841: Hhadow stack vs exceptions from emulation stubs (bsc#1219885) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1102=1 SUSE-2024-1102=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1102=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1102=1 * Server Applications Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP5-2024-1102=1 ## Package List: * openSUSE Leap 15.5 (aarch64 x86_64 i586) * xen-libs-4.17.3_08-150500.3.27.1 * xen-devel-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-domU-debuginfo-4.17.3_08-150500.3.27.1 * xen-tools-domU-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (x86_64) * xen-libs-32bit-debuginfo-4.17.3_08-150500.3.27.1 * xen-libs-32bit-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (aarch64 x86_64) * xen-tools-4.17.3_08-150500.3.27.1 * xen-4.17.3_08-150500.3.27.1 * xen-doc-html-4.17.3_08-150500.3.27.1 * xen-tools-debuginfo-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (aarch64_ilp32) * xen-libs-64bit-4.17.3_08-150500.3.27.1 * xen-libs-64bit-debuginfo-4.17.3_08-150500.3.27.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * xen-libs-4.17.3_08-150500.3.27.1 * Basesystem Module 15-SP5 (x86_64) * xen-libs-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-domU-debuginfo-4.17.3_08-150500.3.27.1 * xen-tools-domU-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * Server Applications Module 15-SP5 (x86_64) * xen-devel-4.17.3_08-150500.3.27.1 * xen-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-4.17.3_08-150500.3.27.1 * xen-tools-debuginfo-4.17.3_08-150500.3.27.1 * Server Applications Module 15-SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_08-150500.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2023-46841.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1027519 *https://bugzilla.suse.com/show_bug.cgi?id=1219885 * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . Enhancements bolster security for Xen, addressing several vulnerabilities such as register file data sampling and GhostRace concerns.. openSUSE Security Update, Xen Data Sampling, Race Conditions Fix. . LinuxSecurity.com Team
This update for xen fixes the following issues: CVE-2023-28746: Register File Data Sampling (bsc#1221332) CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334). # Security update for xen Announcement ID: SUSE-SU-2024:1152-1 Rating: moderate References: * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-1152=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1152=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1152=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-1152=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (x86_64) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) *xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (aarch64 x86_64 i586) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-devel-4.14.6_12-150300.3.69.1 * xen-tools-domU-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * xen-tools-domU-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (x86_64) * xen-libs-32bit-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-32bit-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (aarch64 x86_64) * xen-tools-4.14.6_12-150300.3.69.1 * xen-4.14.6_12-150300.3.69.1 * xen-tools-debuginfo-4.14.6_12-150300.3.69.1 * xen-doc-html-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (aarch64_ilp32) * xen-libs-64bit-4.14.6_12-150300.3.69.1 * xen-libs-64bit-debuginfo-4.14.6_12-150300.3.69.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . Critical security updates for openSUSE have arrived to address severe vulnerabilities in xen, specifically targeting issues related to data sampling and race conditions. openSUSE Security, Xen Update, Data Sampling Fix. . LinuxSecurity.com Team
* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 . # Security update for xen Announcement ID: SUSE-SU-2024:1152-1 Rating: moderate References: * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-1152=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1152=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1152=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-1152=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (x86_64) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3(aarch64 x86_64 i586) * xen-debugsource-4.14.6_12-150300.3.69.1 * xen-devel-4.14.6_12-150300.3.69.1 * xen-tools-domU-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-4.14.6_12-150300.3.69.1 * xen-tools-domU-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (x86_64) * xen-libs-32bit-debuginfo-4.14.6_12-150300.3.69.1 * xen-libs-32bit-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (aarch64 x86_64) * xen-tools-4.14.6_12-150300.3.69.1 * xen-4.14.6_12-150300.3.69.1 * xen-tools-debuginfo-4.14.6_12-150300.3.69.1 * xen-doc-html-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_12-150300.3.69.1 * openSUSE Leap 15.3 (aarch64_ilp32) * xen-libs-64bit-4.14.6_12-150300.3.69.1 * xen-libs-64bit-debuginfo-4.14.6_12-150300.3.69.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . A significant Fedora security alert regarding the enhancement of QEMU virtual machine configuration and potential buffer overflow vulnerabilities.. SUSE Security Advisory,xen Update,openSUSE Leap,Security Update. . LinuxSecurity.com Team
* bsc#1027519 * bsc#1220141 * bsc#1221332 * bsc#1221334 . # Security update for xen Announcement ID: SUSE-SU-2024:1105-1 Rating: moderate References: * bsc#1027519 * bsc#1220141 * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves two vulnerabilities and has two security fixes can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register file data sampling. (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1105=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 *xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 * xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise Server 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 * xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 x86_64) * xen-devel-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1027519 * https://bugzilla.suse.com/show_bug.cgi?id=1220141 * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . SUSE patches tackle vulnerabilities in xen with focus on data exposure and speculative execution flaws. Discover more details!. SUSE Linux Enterprise, Xen Security Update, Race Condition Fix. . LinuxSecurity.com Team
x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-29f57f1b4e 2024-03-30 01:43:28.218917 -------------------------------------------------------------------------------- Name : xen Product : Fedora 38 Version : 4.17.2 Release : 8.fc38 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193] -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 14 2024 Michael Young - 4.17.2-8 - x86: Register File Data Sampling [XSA-452, CVE-2023-28746] - GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193] - additional patches so above applies cleanly -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-29f57f1b4e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.