gpp_maybe
Security update for xen
SUSE-SLE-SAP-12-SP1-2017-1533
This update for xen fixes several issues. These security issues were fixed: - CVE-2017-14316: Missing bound check in function `alloc_heap_pages` for an internal array allowed attackers using crafted hypercalls to execute arbitrary code within Xen (XSA-231, bsc#1056278) - CVE-2017-14318: The function __gnttab_cache_flush missed a check for grant tables, allowing a malicious guest to crash the host or for x86 PV guests to potentially escalate privileges (XSA-232, bsc#1056280) - CVE-2017-14317: A race in cxenstored may have cause a double-free allowind for DoS of the xenstored daemon (XSA-233, bsc#1056281). - CVE-2017-14319: An error while handling grant mappings allowed malicious or buggy x86 PV guest to escalate its privileges or crash the hypervisor (XSA-234, bsc#1056282).
-
Release DateSep 14 2017
-
ReferencesBugzilla: 1056282, 1056281, 1056280, 1056278
CVEs: CVE-2017-14316, CVE-2017-14317, CVE-2017-14318, CVE-2017-14319 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.1 x86_64
-
Packagesxen
Xen Virtualization: Hypervisor (aka VMM aka Microkernel)xen-doc-html4.5.5_16-22.28.1 lock rpm lock src
Xen Virtualization: HTML documentationxen-kmp-default4.5.5_16-22.28.1 lock rpm
Xen para-virtual device drivers for fully virtualized guestsxen-libs4.5.5_16_k3.12.74_60.64.57-22.28.1 lock rpm
Xen Virtualization: Librariesxen-libs-32bit4.5.5_16-22.28.1 lock rpm
Xen Virtualization: Librariesxen-tools4.5.5_16-22.28.1 lock rpm
Xen Virtualization: Control tools for domain 0xen-tools-domU4.5.5_16-22.28.1 lock rpm
Xen Virtualization: Control tools for domain U4.5.5_16-22.28.1 lock rpm