Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ec271ef07b 2025-11-09 03:17:35.195054+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 42 Version : 4.19.3 Release : 8.fc42 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Michael Young - 4.19.3-8 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.19.3-6 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ec271ef07b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-48dc1c8c79 2025-11-07 02:35:35.301730+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 41 Version : 4.19.3 Release : 7.fc41 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Michael Young - 4.19.3-7 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.19.3-5 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-48dc1c8c79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves five vulnerabilities can now be installed.. # Security update for xen Announcement ID: SUSE-SU-2025:3843-1 Release Date: 2025-10-28T16:40:50Z Rating: important References: * bsc#1248807 * bsc#1251271 Cross-References: * CVE-2025-27466 * CVE-2025-58142 * CVE-2025-58143 * CVE-2025-58147 * CVE-2025-58148 CVSS scores: * CVE-2025-27466 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-27466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58142 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-58142 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58147 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2025-58148 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves five vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2025-58147, CVE-2025-58148: Fixed incorrect input sanitisation in Viridian hypercalls (bsc#1251271, XSA-475) * CVE-2025-27466,CVE-2025-58142, CVE-2025-58143: Fixed mutiple vulnerabilities in the Viridian interface (bsc#1248807, XSA-472) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3843=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3843=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3843=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3843=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3843=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64 i586) * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4(x86_64) * xen-libs-32bit-4.16.7_04-150400.4.75.1 * xen-libs-32bit-debuginfo-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64 x86_64) * xen-doc-html-4.16.7_04-150400.4.75.1 * xen-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64_ilp32) * xen-libs-64bit-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-64bit-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 *xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27466.html * https://www.suse.com/security/cve/CVE-2025-58142.html * https://www.suse.com/security/cve/CVE-2025-58143.html * https://www.suse.com/security/cve/CVE-2025-58147.html * https://www.suse.com/security/cve/CVE-2025-58148.html * https://bugzilla.suse.com/show_bug.cgi?id=1248807 * https://bugzilla.suse.com/show_bug.cgi?id=1251271 . Update for openSUSE addresses five important issues in Xen with significant impact on security features.. openSUSE,Linux vulnerabilities,xen,security update. . Severity: Important. LinuxSecurity.com Team
Maher Azzouzi discovered that missing input sanitising in the Enlightenment window manager may result in local privilege escalation to root. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5233-1
Jan-Niklas Sohn discovered that missing input sanitising in the XInput extension of the X.org X server may result in privilege escalation if the X server is running privileged. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4893-1
It was discovered that insufficient input sanitising in libevt, a library to access the Windows Event Log (EVT) format, could result in denial of service or the execution of arbitrary code if a malformed EVT file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4160-1
This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4040-1
Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3546-1
Get the latest Linux and open source security news straight to your inbox.