gpp_maybe Security update for xen
SUSE-SLE-Module-Server-Applications-15-SP4-2022-4007


This update for xen fixes the following issues: - CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806). - CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807). - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488) - CVE-2022-42320: xen: Xenstore: Guests can get access to Xenstore nodes of deleted domains (bsc#1204489) - CVE-2022-42321: xen: Xenstore: Guests can crash xenstored via exhausting the stack (bsc#1204490) - CVE-2022-42322,CVE-2022-42323: xen: Xenstore: cooperating guests can create arbitrary numbers of nodes (bsc#1204494) - CVE-2022-42325,CVE-2022-42326: xen: Xenstore: Guests can create arbitrary number of nodes via transactions (bsc#1204496) - xen: Frontends vulnerable to backends (bsc#1193923).


cloud_download Downloads

Server Applications Module 15.4 x86_64
  • Packages
    xen
    Xen Virtualization: Hypervisor (aka VMM aka Microkernel)
    4.16.2_08-150400.4.16.1 lock rpm lock src
    xen-devel
    Xen Virtualization: Headers and libraries for development
    4.16.2_08-150400.4.16.1 lock rpm
    xen-tools
    Xen Virtualization: Control tools for domain 0
    4.16.2_08-150400.4.16.1 lock rpm
    xen-tools-xendomains-wait-disk
    Adds a new xendomains-wait-disks.service
    4.16.2_08-150400.4.16.1 lock rpm