gpp_maybe
Security update for xen
SUSE-SLE-SERVER-12-2019-1348
This update for xen fixes the following issues: Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331) - CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS) - CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS) - CVE-2018-12130: Microarchitectural Load Port Data Sampling (MLPDS) - CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM) These updates contain the XEN Hypervisor adjustments, that additionally also use CPU Microcode updates. The mitigation can be controlled via the "mds" commandline option, see the documentation. For more information on this set of vulnerabilities, check out https://www.suse.com/support/kb/doc/?id=7023736 Other fixes: - CVE-2018-20815: Fixed a heap buffer overflow while loading device tree blob (bsc#1130680). - Added upstream bug fix (bsc#1027519).
-
Release DateMay 24 2019
-
ReferencesBugzilla: 1027519, 1130680, 1111331
CVEs: CVE-2019-11091, CVE-2018-20815, CVE-2018-12130, CVE-2018-12127, CVE-2018-12126 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server LTSS 12 x86_64
-
Packagesxen
Xen Virtualization: Hypervisor (aka VMM aka Microkernel)xen-doc-html4.4.4_40-22.80.1 lock rpm lock src
Xen Virtualization: HTML documentationxen-kmp-default4.4.4_40-22.80.1 lock rpm
Xen para-virtual device drivers for fully virtualized guestsxen-libs4.4.4_40_k3.12.61_52.149-22.80.1 lock rpm
Xen Virtualization: Librariesxen-libs-32bit4.4.4_40-22.80.1 lock rpm
Xen Virtualization: Librariesxen-tools4.4.4_40-22.80.1 lock rpm
Xen Virtualization: Control tools for domain 0xen-tools-domU4.4.4_40-22.80.1 lock rpm
Xen Virtualization: Control tools for domain U4.4.4_40-22.80.1 lock rpm