Oval Definition:oval:org.opensuse.security:def:56779
Revision Date:2020-12-01Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

Security issues fixed:

- CVE-2018-3639: Spectre V4 – Speculative Store Bypass aka 'Memory Disambiguation' (bsc#1092631)

This feature can be controlled by the 'ssbd=on/off' commandline flag for the XEN hypervisor.
- CVE-2018-10982: x86 vHPET interrupt injection errors (XSA-261 bsc#1090822)
- CVE-2018-10981: qemu may drive Xen into unbounded loop (XSA-262 bsc#1090823)

Other bugfixes:

- Upstream patches from Jan (bsc#1027519)
- additional fixes related to Page Table Isolation (XPTI). (bsc#1074562 XSA-254)
- qemu-system-i386 cannot handle more than 4 HW NICs (bsc#1090296)
Family:unixClass:patch
Status:Reference(s):1005070
1005072
1005076
1020427
1021741
1025109
1025311
1027519
1028184
1028656
1030624
1032075
1034866
1034908
1035406
1035950
1036211
1036244
1037242
1037334
1037336
1039495
1042159
1042800
1042801
1043073
1043296
1045035
1046636
1047674
1048902
1049381
1054724
1056334
1057378
1057585
1062069
1063122
1074562
1090296
1090822
1090823
1092631
1123371
1123377
1123378
1139083
1155094
1159352
1162224
1162367
1162825
1165894
1173998
1175664
1175665
1175671
934524
934525
934526
934527
934528
934529
959888
967970
975500
985657
986566
987394
989980
994418
994605
998677
CVE-2014-9732
CVE-2015-2304
CVE-2015-4467
CVE-2015-4468
CVE-2015-4469
CVE-2015-4470
CVE-2015-4471
CVE-2015-4472
CVE-2015-5185
CVE-2015-7575
CVE-2016-2533
CVE-2016-3189
CVE-2016-4009
CVE-2016-5418
CVE-2016-5759
CVE-2016-5844
CVE-2016-6153
CVE-2016-6250
CVE-2016-6834
CVE-2016-6835
CVE-2016-8687
CVE-2016-8688
CVE-2016-8689
CVE-2016-9602
CVE-2016-9603
CVE-2017-10664
CVE-2017-10806
CVE-2017-10911
CVE-2017-11334
CVE-2017-11434
CVE-2017-12809
CVE-2017-13672
CVE-2017-14167
CVE-2017-15038
CVE-2017-15289
CVE-2017-5579
CVE-2017-5973
CVE-2017-5987
CVE-2017-6505
CVE-2017-7377
CVE-2017-7471
CVE-2017-7493
CVE-2017-7718
CVE-2017-7980
CVE-2017-8086
CVE-2017-8112
CVE-2017-8309
CVE-2017-8379
CVE-2017-8380
CVE-2017-8422
CVE-2017-9330
CVE-2017-9373
CVE-2017-9374
CVE-2017-9375
CVE-2017-9503
CVE-2018-10981
CVE-2018-10982
CVE-2018-16890
CVE-2018-3639
CVE-2019-12900
CVE-2019-16775
CVE-2019-16776
CVE-2019-16777
CVE-2019-18348
CVE-2019-3822
CVE-2019-3823
CVE-2019-9674
CVE-2020-13753
CVE-2020-15810
CVE-2020-15811
CVE-2020-24606
CVE-2020-8492
CVE-2020-9802
CVE-2020-9803
CVE-2020-9805
CVE-2020-9806
CVE-2020-9807
CVE-2020-9843
CVE-2020-9850
SUSE-SU-2016:0011-1
SUSE-SU-2016:0149-1
SUSE-SU-2016:1945-1
SUSE-SU-2016:2911-1
SUSE-SU-2017:1335-1
SUSE-SU-2017:2946-1
SUSE-SU-2018:1456-1
SUSE-SU-2019:0249-1
SUSE-SU-2019:1955-1
SUSE-SU-2019:2334-1
SUSE-SU-2020:0247-1
SUSE-SU-2020:0854-1
SUSE-SU-2020:2069-1
SUSE-SU-2020:2471-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND binutils-2.29.1-lp150.4 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libtasn1-4.13-lp151.4.3 is installed
  • OR libtasn1-6-4.13-lp151.4.3 is installed
  • OR libtasn1-6-32bit-4.13-lp151.4.3 is installed
  • OR libtasn1-devel-4.13-lp151.4.3 is installed
  • OR libtasn1-devel-32bit-4.13-lp151.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • xen-4.9.2_06-3.32 is installed
  • OR xen-libs-4.9.2_06-3.32 is installed
  • OR xen-libs-32bit-4.9.2_06-3.32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libsqlite3-0-3.8.10.2-3 is installed
  • OR libsqlite3-0-32bit-3.8.10.2-3 is installed
  • OR sqlite3-3.8.10.2-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • qemu-2.3.1-33.3 is installed
  • OR qemu-block-curl-2.3.1-33.3 is installed
  • OR qemu-block-rbd-2.3.1-33.3 is installed
  • OR qemu-guest-agent-2.3.1-33.3 is installed
  • OR qemu-ipxe-1.0.0-33.3 is installed
  • OR qemu-kvm-2.3.1-33.3 is installed
  • OR qemu-lang-2.3.1-33.3 is installed
  • OR qemu-ppc-2.3.1-33.3 is installed
  • OR qemu-s390-2.3.1-33.3 is installed
  • OR qemu-seabios-1.8.1-33.3 is installed
  • OR qemu-sgabios-8-33.3 is installed
  • OR qemu-tools-2.3.1-33.3 is installed
  • OR qemu-vgabios-1.8.1-33.3 is installed
  • OR qemu-x86-2.3.1-33.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND kdump-0.8.15-28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • perl-5.18.2-12.14 is installed
  • OR perl-32bit-5.18.2-12.14 is installed
  • OR perl-base-5.18.2-12.14 is installed
  • OR perl-doc-5.18.2-12.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.46 is installed
  • OR libopenssl1_0_0-1.0.2j-60.46 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.46 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.46 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.46 is installed
  • OR openssl-1.0.2j-60.46 is installed
  • OR openssl-doc-1.0.2j-60.46 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • libvirt-2.0.0-27.45 is installed
  • OR libvirt-client-2.0.0-27.45 is installed
  • OR libvirt-daemon-2.0.0-27.45 is installed
  • OR libvirt-daemon-config-network-2.0.0-27.45 is installed
  • OR libvirt-daemon-config-nwfilter-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-interface-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-libxl-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-lxc-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-network-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-nodedev-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-nwfilter-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-qemu-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-secret-2.0.0-27.45 is installed
  • OR libvirt-daemon-driver-storage-2.0.0-27.45 is installed
  • OR libvirt-daemon-hooks-2.0.0-27.45 is installed
  • OR libvirt-daemon-lxc-2.0.0-27.45 is installed
  • OR libvirt-daemon-qemu-2.0.0-27.45 is installed
  • OR libvirt-daemon-xen-2.0.0-27.45 is installed
  • OR libvirt-doc-2.0.0-27.45 is installed
  • OR libvirt-lock-sanlock-2.0.0-27.45 is installed
  • OR libvirt-nss-2.0.0-27.45 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • jakarta-taglibs-standard-1.1.1-255 is installed
  • OR jakarta-taglibs-standard-javadoc-1.1.1-255 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.9 is installed
  • OR libssh2-1-32bit-1.4.3-20.9 is installed
  • OR libssh2_org-1.4.3-20.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kernel-default-4.4.180-94.116 is installed
  • OR kernel-default-base-4.4.180-94.116 is installed
  • OR kernel-default-devel-4.4.180-94.116 is installed
  • OR kernel-default-kgraft-4.4.180-94.116 is installed
  • OR kernel-devel-4.4.180-94.116 is installed
  • OR kernel-macros-4.4.180-94.116 is installed
  • OR kernel-source-4.4.180-94.116 is installed
  • OR kernel-syms-4.4.180-94.116 is installed
  • OR kgraft-patch-4_4_180-94_116-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_31-1-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • git-2.26.0-27.27 is installed
  • OR git-core-2.26.0-27.27 is installed
  • OR libpcre2-16-0-10.34-1.3 is installed
  • OR libpcre2-32-0-10.34-1.3 is installed
  • OR libpcre2-8-0-10.34-1.3 is installed
  • OR libpcre2-posix2-10.34-1.3 is installed
  • OR pcre2-10.34-1.3 is installed
  • OR perl-CGI-4.38-1.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libkde4-4.12.0-10 is installed
  • OR libkde4-32bit-4.12.0-10 is installed
  • OR libkdecore4-4.12.0-10 is installed
  • OR libkdecore4-32bit-4.12.0-10 is installed
  • OR libksuseinstall1-4.12.0-10 is installed
  • OR libksuseinstall1-32bit-4.12.0-10 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND python-Pillow-2.8.1-4.9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • ibus-1.5.13-15.11 is installed
  • OR ibus-gtk-1.5.13-15.11 is installed
  • OR ibus-gtk3-1.5.13-15.11 is installed
  • OR ibus-lang-1.5.13-15.11 is installed
  • OR libibus-1_0-5-1.5.13-15.11 is installed
  • OR typelib-1_0-IBus-1_0-1.5.13-15.11 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libfreebl3-3.47.1-58.34 is installed
  • OR libfreebl3-32bit-3.47.1-58.34 is installed
  • OR libfreebl3-hmac-3.47.1-58.34 is installed
  • OR libfreebl3-hmac-32bit-3.47.1-58.34 is installed
  • OR libsoftokn3-3.47.1-58.34 is installed
  • OR libsoftokn3-32bit-3.47.1-58.34 is installed
  • OR libsoftokn3-hmac-3.47.1-58.34 is installed
  • OR libsoftokn3-hmac-32bit-3.47.1-58.34 is installed
  • OR mozilla-nspr-4.23-19.12 is installed
  • OR mozilla-nspr-32bit-4.23-19.12 is installed
  • OR mozilla-nspr-devel-4.23-19.12 is installed
  • OR mozilla-nss-3.47.1-58.34 is installed
  • OR mozilla-nss-32bit-3.47.1-58.34 is installed
  • OR mozilla-nss-certs-3.47.1-58.34 is installed
  • OR mozilla-nss-certs-32bit-3.47.1-58.34 is installed
  • OR mozilla-nss-devel-3.47.1-58.34 is installed
  • OR mozilla-nss-sysinit-3.47.1-58.34 is installed
  • OR mozilla-nss-sysinit-32bit-3.47.1-58.34 is installed
  • OR mozilla-nss-tools-3.47.1-58.34 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.8 is installed
  • OR rubygem-rails-html-sanitizer-1.0.3-8.8 is installed
  • BACK