gpp_maybe
Security update for xen
SUSE-SUSE-MicroOS-5.2-2022-3947
This update for xen fixes the following issues: - CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806) - CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807) - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488) - CVE-2022-42320: xen: Xenstore: Guests can get access to Xenstore nodes of deleted domains (bsc#1204489) - CVE-2022-42321: xen: Xenstore: Guests can crash xenstored via exhausting the stack (bsc#1204490) - CVE-2022-42322,CVE-2022-42323: xen: Xenstore: cooperating guests can create arbitrary numbers of nodes (bsc#1204494) - CVE-2022-42325,CVE-2022-42326: xen: Xenstore: Guests can create arbitrary number of nodes via transactions (bsc#1204496) - xen: Frontends vulnerable to backends (bsc#1193923)
-
Release DateNov 11 2022
-
ReferencesBugzilla: 1027519, 1204487, 1204490, 1204489, 1203806, 1204494, 1203807, 1204496, 1204488, 1204482, 1204485, 1193923
CVEs: CVE-2022-42310, CVE-2022-42323, CVE-2022-42313, CVE-2022-42320, CVE-2022-42309, CVE-2022-42316, CVE-2022-42312, CVE-2022-33748, CVE-2022-42319, CVE-2022-42325, CVE-2022-33746, CVE-2022-42318, CVE-2022-42326, CVE-2022-42321, CVE-2022-42314, CVE-2022-42315, CVE-2022-33747, CVE-2022-42322, CVE-2022-42311, CVE-2022-42317 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.2 x86_64
-
Packages