gpp_maybe Security update for xen
SUSE-SLE-Module-Server-Applications-15-SP7-2026-4090


This update for xen fixes the following issues: Update to version 4.20.3 (jsc#PED-8907). Security issues fixed: - CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). - CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). - CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). - CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). - CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). - CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). - CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). - CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). - CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). - CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). - CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). - CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). - CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841). - pygrub is only supported in de-privileged mode (bsc#1271947). Non security issue fixed: - Xen: Missing upstream bug fixes (bsc#1027519).


cloud_download Downloads

Server Applications Module 15.7 x86_64
  • Packages
    xen
    Xen Virtualization: Hypervisor (aka VMM aka Microkernel)
    4.20.4_04-150700.3.46.1 lock rpm lock src
    xen-devel
    Xen Virtualization: Headers and libraries for development
    4.20.4_04-150700.3.46.1 lock rpm
    xen-tools
    Xen Virtualization: Control tools for domain 0
    4.20.4_04-150700.3.46.1 lock rpm
    xen-tools-xendomains-wait-disk
    Adds a new xendomains-wait-disks.service
    4.20.4_04-150700.3.46.1 lock rpm