Oval Definition:oval:org.opensuse.security:def:50556
Revision Date:2020-12-01Version:1
Title:Recommended update for xen (Important)
Description:

This update for xen fixes the following issues:

Security issues fixed:

- CVE-2018-19967: Fixed HLE constructs that allowed guests to lock up the host, resulting in a Denial of Service (DoS). (XSA-282) (bsc#1114988) - Fixed an issue which could allow malicious PV guests may cause a host crash or gain access to data pertaining to other guests.Additionally, vulnerable configurations are likely to be unstable even in the absence of an attack (bsc#1126198). - Fixed multiple access violations introduced by XENMEM_exchange hypercall which could allow a single PV guest to leak arbitrary amounts of memory, leading to a denial of service (bsc#1126192). - Fixed an issue which could allow a malicious unprivileged guest userspace process to escalate its privilege to that of other userspace processes in the same guest and potentially thereby to that of the guest operating system (bsc#1126201). - Fixed an issue which could allow malicious or buggy x86 PV guest kernels to mount a Denial of Service attack affecting the whole system (bsc#1126197). - Fixed an issue which could allow an untrusted PV domain with access to a physical device to DMA into its own pagetables leading to privilege escalation (bsc#1126195). - Fixed an issue which could allow a malicious or buggy x86 PV guest kernels can mount a Denial of Service attack affecting the whole system (bsc#1126196). - Fixed an issue which could allow malicious 64bit PV guests to cause a host crash (bsc#1127400). - Fixed an issue which could allow malicious or buggy guests with passed through PCI devices to be able to escalate their privileges, crash the host, or access data belonging to other guests. Additionally memory leaks were also possible (bsc#1126140). - Fixed a race condition issue which could allow malicious PV guests to escalate their privilege to that of the hypervisor (bsc#1126141).

Other issues fixed:

- Upstream bug fixes (bsc#1027519) - Fixed an issue where setup of grant_tables and other variables may fail (bsc#1126325). - Added a requirement for xen, xl.cfg firmware='pvgrub32|pvgrub64 (bsc#1127620). - Added Xen cmdline option 'suse_vtsc_tolerance' to avoid TSC emulation for HVM domUs (bsc#1026236).
Family:unixClass:patch
Status:Reference(s):1026236
1027519
1068059
1079730
1087303
1087931
1098403
1101499
1102230
1103203
1107832
1110233
1111025
1111331
1114988
1116319
1116320
1116322
1116324
1120067
1120095
1124194
1126140
1126141
1126192
1126195
1126196
1126197
1126198
1126201
1126325
1127400
1127620
1128935
1128937
1130746
1132657
1132879
1133100
1135247
1141322
1145093
1150137
1158527
1159819
1160467
1160468
1161883
1166751
1171550
1174458
1175070
1175071
1175193
1175194
1176631
1177895
1178074
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-14629
CVE-2018-14633
CVE-2018-16838
CVE-2018-16841
CVE-2018-16851
CVE-2018-16853
CVE-2018-17182
CVE-2018-18508
CVE-2018-19967
CVE-2019-10222
CVE-2019-11091
CVE-2019-11745
CVE-2019-14896
CVE-2019-14897
CVE-2019-16168
CVE-2019-17006
CVE-2019-9704
CVE-2019-9705
CVE-2020-0556
CVE-2020-11993
CVE-2020-13249
CVE-2020-14339
CVE-2020-14349
CVE-2020-14350
CVE-2020-27153
CVE-2020-2752
CVE-2020-2760
CVE-2020-2812
CVE-2020-2814
CVE-2020-9490
SUSE-SU-2018:3272-1
SUSE-SU-2018:4066-1
SUSE-SU-2019:0875-1
SUSE-SU-2019:1248-1
SUSE-SU-2019:1389-2
SUSE-SU-2019:1476-1
SUSE-SU-2019:2247-1
SUSE-SU-2019:2533-1
SUSE-SU-2019:3395-1
SUSE-SU-2020:2265-1
SUSE-SU-2020:2269-1
SUSE-SU-2020:3067-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Module for additional PackageHub packages 15
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Live Patching 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Module for Server Applications 15 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15 SP1
SUSE Linux Enterprise Workstation Extension 15 SP2
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • libsndfile-1.0.20-2.10 is installed
  • OR libsndfile-32bit-1.0.20-2.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • MozillaFirefox-38.7.0esr-37 is installed
  • OR MozillaFirefox-translations-38.7.0esr-37 is installed
  • OR libfreebl3-3.20.2-28 is installed
  • OR libfreebl3-32bit-3.20.2-28 is installed
  • OR libsoftokn3-3.20.2-28 is installed
  • OR libsoftokn3-32bit-3.20.2-28 is installed
  • OR mozilla-nspr-4.12-24 is installed
  • OR mozilla-nspr-32bit-4.12-24 is installed
  • OR mozilla-nss-3.20.2-28 is installed
  • OR mozilla-nss-32bit-3.20.2-28 is installed
  • OR mozilla-nss-tools-3.20.2-28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • emacs-24.3-14 is installed
  • OR emacs-info-24.3-14 is installed
  • OR emacs-x11-24.3-14 is installed
  • OR etags-24.3-14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • bind-libs-9.9.6P1-30 is installed
  • OR bind-libs-32bit-9.9.6P1-30 is installed
  • OR bind-utils-9.9.6P1-30 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND busybox-1.21.1-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • imobiledevice-tools-1.2.0-7 is installed
  • OR libimobiledevice6-1.2.0-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • alsa-1.0.27.2-15 is installed
  • OR libasound2-1.0.27.2-15 is installed
  • OR libasound2-32bit-1.0.27.2-15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for additional PackageHub packages 15 is installed
  • AND Package Information
  • samba-4.7.11+git.140.6bd0e5b30d8-4.21 is installed
  • OR samba-python-4.7.11+git.140.6bd0e5b30d8-4.21 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 is installed
  • AND Package Information
  • xen-4.10.3_02-3.14 is installed
  • OR xen-libs-4.10.3_02-3.14 is installed
  • OR xen-tools-domU-4.10.3_02-3.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libipa_hbac-devel-1.16.1-3.24 is installed
  • OR libipa_hbac0-1.16.1-3.24 is installed
  • OR libsss_certmap-devel-1.16.1-3.24 is installed
  • OR libsss_certmap0-1.16.1-3.24 is installed
  • OR libsss_idmap-devel-1.16.1-3.24 is installed
  • OR libsss_idmap0-1.16.1-3.24 is installed
  • OR libsss_nss_idmap-devel-1.16.1-3.24 is installed
  • OR libsss_nss_idmap0-1.16.1-3.24 is installed
  • OR libsss_simpleifp-devel-1.16.1-3.24 is installed
  • OR libsss_simpleifp0-1.16.1-3.24 is installed
  • OR python3-sssd-config-1.16.1-3.24 is installed
  • OR sssd-1.16.1-3.24 is installed
  • OR sssd-ad-1.16.1-3.24 is installed
  • OR sssd-dbus-1.16.1-3.24 is installed
  • OR sssd-ipa-1.16.1-3.24 is installed
  • OR sssd-krb5-1.16.1-3.24 is installed
  • OR sssd-krb5-common-1.16.1-3.24 is installed
  • OR sssd-ldap-1.16.1-3.24 is installed
  • OR sssd-proxy-1.16.1-3.24 is installed
  • OR sssd-tools-1.16.1-3.24 is installed
  • OR sssd-wbclient-1.16.1-3.24 is installed
  • OR sssd-wbclient-devel-1.16.1-3.24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 is installed
  • AND Package Information
  • kernel-livepatch-4_12_14-25_3-default-5-2 is installed
  • OR kernel-livepatch-SLE15_Update_1-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • cronie-1.5.1-6.7 is installed
  • OR cronie-anacron-1.5.1-6.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • bluez-5.48-13.3 is installed
  • OR bluez-auto-enable-devices-5.48-13.3 is installed
  • OR bluez-devel-32bit-5.48-13.3 is installed
  • OR bluez-test-5.48-13.3 is installed
  • OR libbluetooth3-32bit-5.48-13.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 is installed
  • AND Package Information
  • xen-4.10.3_04-3.19 is installed
  • OR xen-devel-4.10.3_04-3.19 is installed
  • OR xen-tools-4.10.3_04-3.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • apache2-2.4.33-3.41 is installed
  • OR apache2-devel-2.4.33-3.41 is installed
  • OR apache2-doc-2.4.33-3.41 is installed
  • OR apache2-prefork-2.4.33-3.41 is installed
  • OR apache2-utils-2.4.33-3.41 is installed
  • OR apache2-worker-2.4.33-3.41 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND Package Information
  • libecpg6-12.4-8.6 is installed
  • OR postgresql12-12.4-8.6 is installed
  • OR postgresql12-contrib-12.4-8.6 is installed
  • OR postgresql12-devel-12.4-8.6 is installed
  • OR postgresql12-docs-12.4-8.6 is installed
  • OR postgresql12-plperl-12.4-8.6 is installed
  • OR postgresql12-plpython-12.4-8.6 is installed
  • OR postgresql12-pltcl-12.4-8.6 is installed
  • OR postgresql12-server-12.4-8.6 is installed
  • OR postgresql12-server-devel-12.4-8.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND apache-commons-httpclient-3.1-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • libmysqlclient-devel-10.0.31-29.3 is installed
  • OR libmysqlclient18-10.0.31-29.3 is installed
  • OR libmysqlclient18-32bit-10.0.31-29.3 is installed
  • OR libmysqlclient_r18-10.0.31-29.3 is installed
  • OR libmysqld-devel-10.0.31-29.3 is installed
  • OR libmysqld18-10.0.31-29.3 is installed
  • OR mariadb-10.0.31-29.3 is installed
  • OR mariadb-client-10.0.31-29.3 is installed
  • OR mariadb-errormessages-10.0.31-29.3 is installed
  • OR mariadb-tools-10.0.31-29.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND apache2-mod_jk-1.2.40-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • ntp-4.2.8p11-64.5 is installed
  • OR ntp-doc-4.2.8p11-64.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • cups-filters-1.0.58-15.2 is installed
  • OR cups-filters-cups-browsed-1.0.58-15.2 is installed
  • OR cups-filters-foomatic-rip-1.0.58-15.2 is installed
  • OR cups-filters-ghostscript-1.0.58-15.2 is installed
  • OR libqpdf18-7.1.1-3.3 is installed
  • OR qpdf-7.1.1-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_109-default-2-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_29-2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • cyrus-sasl-2.1.26-7 is installed
  • OR cyrus-sasl-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-crammd5-2.1.26-7 is installed
  • OR cyrus-sasl-crammd5-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-digestmd5-2.1.26-7 is installed
  • OR cyrus-sasl-gssapi-2.1.26-7 is installed
  • OR cyrus-sasl-gssapi-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-otp-2.1.26-7 is installed
  • OR cyrus-sasl-otp-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-plain-2.1.26-7 is installed
  • OR cyrus-sasl-plain-32bit-2.1.26-7 is installed
  • OR cyrus-sasl-saslauthd-2.1.26-7 is installed
  • OR cyrus-sasl-sqlauxprop-2.1.26-7 is installed
  • OR cyrus-sasl-sqlauxprop-32bit-2.1.26-7 is installed
  • OR libsasl2-3-2.1.26-7 is installed
  • OR libsasl2-3-32bit-2.1.26-7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libjpeg-turbo-1.5.3-31.19 is installed
  • OR libjpeg62-62.2.0-31.19 is installed
  • OR libjpeg62-32bit-62.2.0-31.19 is installed
  • OR libjpeg62-turbo-1.5.3-31.19 is installed
  • OR libjpeg8-8.1.2-31.19 is installed
  • OR libjpeg8-32bit-8.1.2-31.19 is installed
  • OR libturbojpeg0-8.1.2-31.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.55-38.44 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.55-38.44 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.55-38.44 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.55-38.44 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_180-94_103-default-2-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_28-2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • apache2-2.4.23-29.40 is installed
  • OR apache2-doc-2.4.23-29.40 is installed
  • OR apache2-example-pages-2.4.23-29.40 is installed
  • OR apache2-prefork-2.4.23-29.40 is installed
  • OR apache2-utils-2.4.23-29.40 is installed
  • OR apache2-worker-2.4.23-29.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15-LTSS is installed
  • AND Package Information
  • xen-4.10.4_14-3.38 is installed
  • OR xen-devel-4.10.4_14-3.38 is installed
  • OR xen-libs-4.10.4_14-3.38 is installed
  • OR xen-tools-4.10.4_14-3.38 is installed
  • OR xen-tools-domU-4.10.4_14-3.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • freeradius-server-3.0.16-3.6 is installed
  • OR freeradius-server-devel-3.0.16-3.6 is installed
  • OR freeradius-server-krb5-3.0.16-3.6 is installed
  • OR freeradius-server-ldap-3.0.16-3.6 is installed
  • OR freeradius-server-libs-3.0.16-3.6 is installed
  • OR freeradius-server-mysql-3.0.16-3.6 is installed
  • OR freeradius-server-perl-3.0.16-3.6 is installed
  • OR freeradius-server-postgresql-3.0.16-3.6 is installed
  • OR freeradius-server-python-3.0.16-3.6 is installed
  • OR freeradius-server-sqlite-3.0.16-3.6 is installed
  • OR freeradius-server-utils-3.0.16-3.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • LibVNCServer-0.9.10-4.19 is installed
  • OR libvncclient0-0.9.10-4.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND Package Information
  • kernel-default-5.3.18-24.24 is installed
  • OR kernel-default-extra-5.3.18-24.24 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • openstack-trove-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-api-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-conductor-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-guestagent-4.0.1~a0~dev2-2 is installed
  • OR openstack-trove-taskmanager-4.0.1~a0~dev2-2 is installed
  • OR python-trove-4.0.1~a0~dev2-2 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • libwireshark9-2.4.9-48.29 is installed
  • OR libwiretap7-2.4.9-48.29 is installed
  • OR libwscodecs1-2.4.9-48.29 is installed
  • OR libwsutil8-2.4.9-48.29 is installed
  • OR wireshark-2.4.9-48.29 is installed
  • OR wireshark-gtk-2.4.9-48.29 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • bzip2-1.0.6-30.8 is installed
  • OR bzip2-doc-1.0.6-30.8 is installed
  • OR libbz2-1-1.0.6-30.8 is installed
  • OR libbz2-1-32bit-1.0.6-30.8 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND ucode-intel-20190618-13.47 is installed
  • BACK