An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2296-1 Rating: important References: #1027519 #1199965 #1199966 Cross-References: CVE-2022-26362 CVE-2022-26363 CVE-2022-26364 CVSS scores: CVE-2022-26362 (NVD) : 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-26362 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-26363 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-26363 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-26364 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-26364 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for xen fixes the following issues: - CVE-2022-26362: Fixed race condition in typeref acquisition (bsc#1199965) - CVE-2022-26363, CVE-2022-26364: Fixed insufficient care with non-coherent mappings (bsc#1199966) Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods likeYaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2296=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-2296=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-2296=1 Package List: - openSUSE Leap 15.4 (aarch64 x86_64): xen-4.16.1_04-150400.4.5.2 xen-debugsource-4.16.1_04-150400.4.5.2 xen-devel-4.16.1_04-150400.4.5.2 xen-doc-html-4.16.1_04-150400.4.5.2 xen-libs-4.16.1_04-150400.4.5.2 xen-libs-debuginfo-4.16.1_04-150400.4.5.2 xen-tools-4.16.1_04-150400.4.5.2 xen-tools-debuginfo-4.16.1_04-150400.4.5.2 xen-tools-domU-4.16.1_04-150400.4.5.2 xen-tools-domU-debuginfo-4.16.1_04-150400.4.5.2 - openSUSE Leap 15.4 (noarch): xen-tools-xendomains-wait-disk-4.16.1_04-150400.4.5.2 - openSUSE Leap 15.4 (x86_64): xen-libs-32bit-4.16.1_04-150400.4.5.2 xen-libs-32bit-debuginfo-4.16.1_04-150400.4.5.2 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (noarch): xen-tools-xendomains-wait-disk-4.16.1_04-150400.4.5.2 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (x86_64): xen-4.16.1_04-150400.4.5.2 xen-debugsource-4.16.1_04-150400.4.5.2 xen-devel-4.16.1_04-150400.4.5.2 xen-tools-4.16.1_04-150400.4.5.2 xen-tools-debuginfo-4.16.1_04-150400.4.5.2 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (x86_64): xen-debugsource-4.16.1_04-150400.4.5.2 xen-libs-4.16.1_04-150400.4.5.2 xen-libs-debuginfo-4.16.1_04-150400.4.5.2 xen-tools-domU-4.16.1_04-150400.4.5.2 xen-tools-domU-debuginfo-4.16.1_04-150400.4.5.2 References: https://www.suse.com/security/cve/CVE-2022-26362.html https://www.suse.com/security/cve/CVE-2022-26363.html https://www.suse.com/security/cve/CVE-2022-26364.html https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1199965 https://bugzilla.suse.com/1199966 . SUSE Security Patch for xen addresses urgent vulnerabilities. Don't forget to restart your system after applying the update for optimal results.. SUSE Update, xen Security Fix, Race Condition, Mapping Issues, Patch Instructions. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.