Explore top 10 tips to secure your open-source projects now. Read More
×
x86: Native Branch History Injection [XSA-456, CVE-2024-2201] update to xen 4.18.2, remove patches now included upstream x86 HVM hypercalls may trigger Xen bug check [XSA-454, CVE-2023-46842] x86: Incorrect logic for BTC/SRSO mitigations [XSA-455, CVE-2024-31142]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a46df5ba2f 2024-04-25 00:59:19.184421 -------------------------------------------------------------------------------- Name : xen Product : Fedora 40 Version : 4.18.2 Release : 1.fc40 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: Native Branch History Injection [XSA-456, CVE-2024-2201] update to xen 4.18.2, remove patches now included upstream x86 HVM hypercalls may trigger Xen bug check [XSA-454, CVE-2023-46842] x86: Incorrect logic for BTC/SRSO mitigations [XSA-455, CVE-2024-31142] -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 9 2024 Michael Young - 4.18.2-1 - x86: Native Branch History Injection [XSA-456, CVE-2024-2201] - update to xen 4.18.2, remove patches now included upstream * Tue Apr 9 2024 Michael Young - 4.18.1-2 - x86 HVM hypercalls may trigger Xen bug check [XSA-454, CVE-2023-46842] - x86: Incorrect logic for BTC/SRSO mitigations [XSA-455, CVE-2024-31142] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a46df5ba2f' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update for xen fixes the following issues: CVE-2023-28746: Register File Data Sampling (bsc#1221332) CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334). # Security update for xen Announcement ID: SUSE-SU-2024:1102-1 Rating: moderate References: * bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2023-46841 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2023-46841 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register File Data Sampling (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) * CVE-2023-46841: Hhadow stack vs exceptions from emulation stubs (bsc#1219885) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1102=1 SUSE-2024-1102=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1102=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1102=1 * Server Applications Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP5-2024-1102=1 ## Package List: * openSUSE Leap 15.5 (aarch64 x86_64 i586) * xen-libs-4.17.3_08-150500.3.27.1 * xen-devel-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-domU-debuginfo-4.17.3_08-150500.3.27.1 * xen-tools-domU-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (x86_64) * xen-libs-32bit-debuginfo-4.17.3_08-150500.3.27.1 * xen-libs-32bit-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (aarch64 x86_64) * xen-tools-4.17.3_08-150500.3.27.1 * xen-4.17.3_08-150500.3.27.1 * xen-doc-html-4.17.3_08-150500.3.27.1 * xen-tools-debuginfo-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_08-150500.3.27.1 * openSUSE Leap 15.5 (aarch64_ilp32) * xen-libs-64bit-4.17.3_08-150500.3.27.1 * xen-libs-64bit-debuginfo-4.17.3_08-150500.3.27.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * xen-libs-4.17.3_08-150500.3.27.1 * Basesystem Module 15-SP5 (x86_64) * xen-libs-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-domU-debuginfo-4.17.3_08-150500.3.27.1 * xen-tools-domU-4.17.3_08-150500.3.27.1 * xen-libs-debuginfo-4.17.3_08-150500.3.27.1 * Server Applications Module 15-SP5 (x86_64) * xen-devel-4.17.3_08-150500.3.27.1 * xen-4.17.3_08-150500.3.27.1 * xen-debugsource-4.17.3_08-150500.3.27.1 * xen-tools-4.17.3_08-150500.3.27.1 * xen-tools-debuginfo-4.17.3_08-150500.3.27.1 * Server Applications Module 15-SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_08-150500.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2023-46841.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1027519 *https://bugzilla.suse.com/show_bug.cgi?id=1219885 * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . Enhancements bolster security for Xen, addressing several vulnerabilities such as register file data sampling and GhostRace concerns.. openSUSE Security Update, Xen Data Sampling, Race Conditions Fix. . LinuxSecurity.com Team
* bsc#1027519 * bsc#1220141 * bsc#1221332 * bsc#1221334 . # Security update for xen Announcement ID: SUSE-SU-2024:1105-1 Rating: moderate References: * bsc#1027519 * bsc#1220141 * bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746 * CVE-2024-2193 CVSS scores: * CVE-2023-28746 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-2193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves two vulnerabilities and has two security fixes can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-28746: Register file data sampling. (bsc#1221332) * CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (bsc#1221334) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-1105=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-1105=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 *xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 * xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise Server 12 SP5 (x86_64) * xen-tools-domU-4.12.4_46-3.106.1 * xen-libs-debuginfo-32bit-4.12.4_46-3.106.1 * xen-tools-debuginfo-4.12.4_46-3.106.1 * xen-libs-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 * xen-4.12.4_46-3.106.1 * xen-tools-domU-debuginfo-4.12.4_46-3.106.1 * xen-doc-html-4.12.4_46-3.106.1 * xen-tools-4.12.4_46-3.106.1 * xen-libs-debuginfo-4.12.4_46-3.106.1 * xen-libs-32bit-4.12.4_46-3.106.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 x86_64) * xen-devel-4.12.4_46-3.106.1 * xen-debugsource-4.12.4_46-3.106.1 ## References: * https://www.suse.com/security/cve/CVE-2023-28746.html * https://www.suse.com/security/cve/CVE-2024-2193.html * https://bugzilla.suse.com/show_bug.cgi?id=1027519 * https://bugzilla.suse.com/show_bug.cgi?id=1220141 * https://bugzilla.suse.com/show_bug.cgi?id=1221332 * https://bugzilla.suse.com/show_bug.cgi?id=1221334 . SUSE patches tackle vulnerabilities in xen with focus on data exposure and speculative execution flaws. Discover more details!. SUSE Linux Enterprise, Xen Security Update, Race Condition Fix. . LinuxSecurity.com Team
update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3a36322c4b 2024-03-23 00:20:56.402948 -------------------------------------------------------------------------------- Name : xen Product : Fedora 40 Version : 4.18.1 Release : 1.fc40 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193] x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 20 2024 Michael Young - 4.18.1-1 - update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream * Wed Mar 13 2024 Michael Young - 4.18.0-7 - x86: Register File Data Sampling [XSA-452, CVE-2023-28746] - GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193] - additional patches so above applies cleanly * Tue Feb 27 2024 Michael Young - 4.18.0-6 - x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2266325 - CVE-2023-46841 xen: x86 shadow stack vs exceptions from emulation stubs https://bugzilla.redhat.com/show_bug.cgi?id=2266325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3a36322c4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1218851 * bsc#1219080 Cross-References: * CVE-2023-46839 . # Security update for xen Announcement ID: SUSE-SU-2024:0266-1 Rating: moderate References: * bsc#1218851 * bsc#1219080 Cross-References: * CVE-2023-46839 * CVE-2023-46840 CVSS scores: * CVE-2023-46839 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2023-46840 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-46839: Fixed phantom functions assigned to incorrect contexts (XSA-449) (bsc#1218851) * CVE-2023-46840: Fixed VT-d: Failure to quarantine devices in !HVM builds (XSA-450) (bsc#1219080) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-266=1 openSUSE-SLE-15.5-2024-266=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-266=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-266=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-266=1 ## Package List: * openSUSE Leap 15.5 (aarch64 x86_64 i586) * xen-tools-domU-debuginfo-4.17.3_04-150500.3.21.1 *xen-debugsource-4.17.3_04-150500.3.21.1 * xen-libs-4.17.3_04-150500.3.21.1 * xen-libs-debuginfo-4.17.3_04-150500.3.21.1 * xen-devel-4.17.3_04-150500.3.21.1 * xen-tools-domU-4.17.3_04-150500.3.21.1 * openSUSE Leap 15.5 (x86_64) * xen-libs-32bit-debuginfo-4.17.3_04-150500.3.21.1 * xen-libs-32bit-4.17.3_04-150500.3.21.1 * openSUSE Leap 15.5 (aarch64 x86_64) * xen-tools-debuginfo-4.17.3_04-150500.3.21.1 * xen-4.17.3_04-150500.3.21.1 * xen-tools-4.17.3_04-150500.3.21.1 * xen-doc-html-4.17.3_04-150500.3.21.1 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_04-150500.3.21.1 * openSUSE Leap 15.5 (aarch64_ilp32) * xen-libs-64bit-debuginfo-4.17.3_04-150500.3.21.1 * xen-libs-64bit-4.17.3_04-150500.3.21.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-libs-debuginfo-4.17.3_04-150500.3.21.1 * xen-debugsource-4.17.3_04-150500.3.21.1 * xen-libs-4.17.3_04-150500.3.21.1 * Basesystem Module 15-SP5 (x86_64) * xen-tools-domU-debuginfo-4.17.3_04-150500.3.21.1 * xen-debugsource-4.17.3_04-150500.3.21.1 * xen-libs-4.17.3_04-150500.3.21.1 * xen-libs-debuginfo-4.17.3_04-150500.3.21.1 * xen-tools-domU-4.17.3_04-150500.3.21.1 * Server Applications Module 15-SP5 (x86_64) * xen-4.17.3_04-150500.3.21.1 * xen-debugsource-4.17.3_04-150500.3.21.1 * xen-devel-4.17.3_04-150500.3.21.1 * xen-tools-4.17.3_04-150500.3.21.1 * xen-tools-debuginfo-4.17.3_04-150500.3.21.1 * Server Applications Module 15-SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.3_04-150500.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46839.html * https://www.suse.com/security/cve/CVE-2023-46840.html * https://bugzilla.suse.com/show_bug.cgi?id=1218851 * https://bugzilla.suse.com/show_bug.cgi?id=1219080 . SUSE issues a significant patch regarding xen to resolve pressing vulnerabilities. Prompt updates advised.. SUSE Linux, Xen Security Update, SUSE Patch Notice. . LinuxSecurity.com Team
This update for xen fixes the following issues: CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744).. # Security update for xen Announcement ID: SUSE-SU-2023:4174-1 Rating: important References: * bsc#1215744 * bsc#1215746 * bsc#1215747 * bsc#1215748 Cross-References: * CVE-2023-34323 * CVE-2023-34325 * CVE-2023-34326 * CVE-2023-34327 * CVE-2023-34328 CVSS scores: * CVE-2023-34323 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-34325 ( SUSE ): 5.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2023-34326 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-34327 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-34328 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Proxy 4.2 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Server 4.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744). * CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746). * CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443) (bsc#1215747). * CVE-2023-34327, CVE-2023-34328: Fixed multipleissues with AMD x86 debugging functionality for guests (XSA-444) (bsc#1215748). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-4174=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4174=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4174=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4174=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4174=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4174=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4174=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4174=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4174=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4174=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4174=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4174=1 ## Package List: * openSUSE Leap 15.3 (aarch64 x86_64 i586) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 *xen-devel-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (x86_64) * xen-libs-32bit-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-32bit-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (aarch64 x86_64) * xen-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-doc-html-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (aarch64_ilp32) * xen-libs-64bit-4.14.6_06-150300.3.57.1 * xen-libs-64bit-debuginfo-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 *xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Proxy 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Proxy 4.2 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Retail Branch Server 4.2 (noarch) *xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Server 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Server 4.2 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Enterprise Storage 7.1 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Enterprise Storage 7.1 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro 5.1 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 ## References: * https://www.suse.com/security/cve/CVE-2023-34323.html * https://www.suse.com/security/cve/CVE-2023-34325.html * https://www.suse.com/security/cve/CVE-2023-34326.html * https://www.suse.com/security/cve/CVE-2023-34327.html * https://www.suse.com/security/cve/CVE-2023-34328.html * https://bugzilla.suse.com/show_bug.cgi?id=1215744 *https://bugzilla.suse.com/show_bug.cgi?id=1215746 * https://bugzilla.suse.com/show_bug.cgi?id=1215747 * https://bugzilla.suse.com/show_bug.cgi?id=1215748 . Urgent advisory for openSUSE regarding significant vulnerabilities in xen that could lead to system instability and various parsing failures. Ensure you update immediately.. xen Security Update, openSUSE Update, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team
An update that solves 11 vulnerabilities and has 7 fixes is now available. . openSUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2923-1 Rating: important References: #1027519 #1176189 #1179246 #1183243 #1183877 #1185682 #1186428 #1186429 #1186433 #1186434 #1187406 #1188050 #1189373 #1189376 #1189378 #1189380 #1189381 #1189882 Cross-References: CVE-2021-0089 CVE-2021-28690 CVE-2021-28692 CVE-2021-28693 CVE-2021-28694 CVE-2021-28695 CVE-2021-28696 CVE-2021-28697 CVE-2021-28698 CVE-2021-28699 CVE-2021-28700 CVSS scores: CVE-2021-0089 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVE-2021-28694 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28695 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28696 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28697 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-28698 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-28699 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-28700 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves 11 vulnerabilities and has 7 fixes is now available. Description: This update for xen fixes the following issues: Update to Xen 4.13.3 general bug fix release (bsc#1027519). Security issues fixed: - CVE-2021-28693: xen/arm: Boot modules are not scrubbed (bsc#1186428) - CVE-2021-28692: xen: inappropriate x86 IOMMU timeout detection / handling (bsc#1186429) - CVE-2021-0089: xen: Speculative Code Store Bypass (bsc#1186433) - CVE-2021-28690: xen: x86: TSX Async Abort protections not restored after S3 (bsc#1186434) - CVE-2021-28694,CVE-2021-28695,CVE-2021-28696: IOMMU page mapping issues on x86 (XSA-378)(bsc#1189373). - CVE-2021-28697: grant table v2 status pages may remain accessible after de-allocation (XSA-379)(bsc#1189376). - CVE-2021-28698: long running loops in grant table handling (XSA-380)(bsc#1189378). - CVE-2021-28699: inadequate grant-v2 status frames array bounds check (XSA-382)(bsc#1189380). - CVE-2021-28700: No memory limit for dom0less domUs (XSA-383)(bsc#1189381). Other issues fixed: - Fixed "Panic on CPU 0: IO-APIC + timer doesn't work!" (bsc#1180491) - Fixed an issue with xencommons, where file format expecations by fillup did not allign (bsc#1185682) - Fixed shell macro expansion in the spec file, so that ExecStart= in xendomains-wait-disks.service is created correctly (bsc#1183877) - Upstream bug fixes (bsc#1027519) - Fixed Xen SLES11SP4 guest hangs on cluster (bsc#1188050). - xl monitoring process exits during xl save -p|-c keep the monitoring process running to cleanup the domU during shutdown (bsc#1176189). - Dom0 hangs when pinning CPUs for dom0 with HVM guest (bsc#1179246). - Some long deprecated commands were finally removed in qemu6. Adjust libxl to use supported commands (bsc#1183243). - Update logrotate.conf, move global options into per-file sections to prevent globbering of global state (bsc#1187406). - Prevent superpage allocation in the LAPIC and ACPI_INFO range (bsc#1189882). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2923=1 Package List: - openSUSE Leap 15.3 (aarch64 x86_64): xen-4.14.2_04-3.9.1 xen-debugsource-4.14.2_04-3.9.1 xen-devel-4.14.2_04-3.9.1 xen-doc-html-4.14.2_04-3.9.1 xen-libs-4.14.2_04-3.9.1 xen-libs-debuginfo-4.14.2_04-3.9.1 xen-tools-4.14.2_04-3.9.1 xen-tools-debuginfo-4.14.2_04-3.9.1 xen-tools-domU-4.14.2_04-3.9.1 xen-tools-domU-debuginfo-4.14.2_04-3.9.1 - openSUSE Leap 15.3 (noarch): xen-tools-xendomains-wait-disk-4.14.2_04-3.9.1 - openSUSE Leap 15.3 (x86_64): xen-libs-32bit-4.14.2_04-3.9.1 xen-libs-32bit-debuginfo-4.14.2_04-3.9.1 References: https://www.suse.com/security/cve/CVE-2021-0089.html https://www.suse.com/security/cve/CVE-2021-28690.html https://www.suse.com/security/cve/CVE-2021-28692.html https://www.suse.com/security/cve/CVE-2021-28693.html https://www.suse.com/security/cve/CVE-2021-28694.html https://www.suse.com/security/cve/CVE-2021-28695.html https://www.suse.com/security/cve/CVE-2021-28696.html https://www.suse.com/security/cve/CVE-2021-28697.html https://www.suse.com/security/cve/CVE-2021-28698.html https://www.suse.com/security/cve/CVE-2021-28699.html https://www.suse.com/security/cve/CVE-2021-28700.html https://bugzilla.suse.com/1027519 https://bugzilla.suse.com/1176189 https://bugzilla.suse.com/1179246 https://bugzilla.suse.com/1183243 https://bugzilla.suse.com/1183877 https://bugzilla.suse.com/1185682 https://bugzilla.suse.com/1186428 https://bugzilla.suse.com/1186429 https://bugzilla.suse.com/1186433 https://bugzilla.suse.com/1186434 https://bugzilla.suse.com/1187406 https://bugzilla.suse.com/1188050 https://bugzilla.suse.com/1189373 https://bugzilla.suse.com/1189376 https://bugzilla.suse.com/1189378 https://bugzilla.suse.com/1189380 https://bugzilla.suse.com/1189381 https://bugzilla.suse.com/1189882 . This Fedora security patch tackles critical concerns within qemu, rectifying various weaknesses and offering solutions..openSUSE Leap,xen security fixes,vulnerability management,security update,xen bugs. . Severity: Important. LinuxSecurity.com Team
An update that solves 6 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14557-1 Rating: important References: #1177409 #1177412 #1177413 #1177414 #1178591 #1178935 #1178963 Cross-References: CVE-2020-25723 CVE-2020-27670 CVE-2020-27671 CVE-2020-27672 CVE-2020-27674 CVE-2020-28368 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves 6 vulnerabilities and has one errata is now available. Description: This update for xen fixes the following issues: - bsc#1178963 - stack corruption from XSA-346 change (XSA-355) - bsc#1178935 - CVE-2020-25723: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c - bsc#1177409 - CVE-2020-27674: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286) - bsc#1177412 - CVE-2020-27672: Race condition in Xen mapping code (XSA-345) - bsc#1177413 - CVE-2020-27671: undue deferral of IOMMU TLB flushes (XSA-346) - bsc#1177414 - CVE-2020-27670: unsafe AMD IOMMU page table updates (XSA-347) - bsc#1178591 - CVE-2020-28368: Intel RAPL sidechannel attack aka PLATYPUS attack aka XSA-351 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-xen-14557=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-xen-14557=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 x86_64): xen-kmp-default-4.4.4_46_3.0.101_108.117-61.58.1 xen-libs-4.4.4_46-61.58.1 xen-tools-domU-4.4.4_46-61.58.1 - SUSE Linux Enterprise Server 11-SP4-LTSS (x86_64): xen-4.4.4_46-61.58.1 xen-doc-html-4.4.4_46-61.58.1 xen-libs-32bit-4.4.4_46-61.58.1 xen-tools-4.4.4_46-61.58.1 - SUSE Linux Enterprise Server 11-SP4-LTSS (i586): xen-kmp-pae-4.4.4_46_3.0.101_108.117-61.58.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64): xen-debuginfo-4.4.4_46-61.58.1 xen-debugsource-4.4.4_46-61.58.1 References: https://www.suse.com/security/cve/CVE-2020-25723.html https://www.suse.com/security/cve/CVE-2020-27670.html https://www.suse.com/security/cve/CVE-2020-27671.html https://www.suse.com/security/cve/CVE-2020-27672.html https://www.suse.com/security/cve/CVE-2020-27674.html https://www.suse.com/security/cve/CVE-2020-28368.html https://bugzilla.suse.com/show_bug.cgi?id=1177409 https://bugzilla.suse.com/show_bug.cgi?id=1177412 https://bugzilla.suse.com/show_bug.cgi?id=1177413 https://bugzilla.suse.com/show_bug.cgi?id=1177414 https://bugzilla.suse.com/show_bug.cgi?id=1178591 https://bugzilla.suse.com/show_bug.cgi?id=1178935 https://bugzilla.suse.com/show_bug.cgi?id=1178963 . Essential SUSE security patch for xen tackles multiple severe vulnerabilities. Uncover the problems and update information today.. SUSE Linux, Xen Security Update, Critical Patch Details. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.