gpp_maybe Security update for xen
SUSE-SLE-SERVER-12-SP3-2017-1500


This update for xen fixes several issues. These security issues were fixed: - CVE-2017-14316: Missing bound check in function `alloc_heap_pages` for an internal array allowed attackers using crafted hypercalls to execute arbitrary code within Xen (XSA-231, bsc#1056278) - CVE-2017-14318: The function __gnttab_cache_flush missed a check for grant tables, allowing a malicious guest to crash the host or for x86 PV guests to potentially escalate privileges (XSA-232, bsc#1056280) - CVE-2017-14317: A race in cxenstored may have cause a double-free allowind for DoS of the xenstored daemon (XSA-233, bsc#1056281). - CVE-2017-14319: An error while handling grant mappings allowed malicious or buggy x86 PV guest to escalate its privileges or crash the hypervisor (XSA-234, bsc#1056282). These non-security issues were fixed: - bsc#1057358: Fixed boot into SUSE Linux Enterprise 12.3 with secure boot - bsc#1055695: Fixed restoring updates for HVM guests for ballooned domUs


cloud_download Downloads

SUSE Linux Enterprise Server 12.3 x86_64
  • Packages
    xen
    Xen Virtualization: Hypervisor (aka VMM aka Microkernel)
    4.9.0_12-3.15.1 lock rpm lock src
    xen-doc-html
    Xen Virtualization: HTML documentation
    4.9.0_12-3.15.1 lock rpm
    xen-libs
    Xen Virtualization: Libraries
    4.9.0_12-3.15.1 lock rpm
    xen-libs-32bit
    Xen Virtualization: Libraries
    4.9.0_12-3.15.1 lock rpm
    xen-tools
    Xen Virtualization: Control tools for domain 0
    4.9.0_12-3.15.1 lock rpm
    xen-tools-domU
    Xen Virtualization: Control tools for domain U
    4.9.0_12-3.15.1 lock rpm