Oval Definition:oval:org.opensuse.security:def:56888
Revision Date:2020-12-01Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

Security issues fixed:

- CVE-2018-19967: Fixed HLE constructs that allowed guests to lock up the host, resulting in a Denial of Service (DoS). (XSA-282) (bsc#1114988) - CVE-2019-6778: Fixed a heap buffer overflow in tcp_emu() found in slirp (bsc#1123157). - Fixed an issue which could allow malicious or buggy guests with passed through PCI devices to be able to escalate their privileges, crash the host, or access data belonging to other guests. Additionally memory leaks were also possible (bsc#1126140). - Fixed a race condition issue which could allow malicious PV guests to escalate their privilege to that of the hypervisor (bsc#1126141). - Fixed an issue which could allow a malicious unprivileged guest userspace process to escalate its privilege to that of other userspace processes in the same guest and potentially thereby to that of the guest operating system (bsc#1126201). - CVE-2019-9824: Fixed an information leak in SLiRP networking implementation which could allow a user/process to read uninitialised stack memory contents (bsc#1129623). - CVE-2018-19961 CVE-2018-19962: Fixed insufficient TLB flushing / improper large page mappings with AMD IOMMUs (XSA-275)(bsc#1115040). - CVE-2018-19965: Fixed denial of service issue from attempting to use INVPCID with a non-canonical addresses (XSA-279)(bsc#1115045). - CVE-2018-19966: Fixed issue introduced by XSA-240 that could have caused conflicts with shadow paging (XSA-280)(bsc#1115047). - Fixed an issue which could allow malicious PV guests may cause a host crash or gain access to data pertaining to other guests.Additionally, vulnerable configurations are likely to be unstable even in the absence of an attack (bsc#1126198). - Fixed multiple access violations introduced by XENMEM_exchange hypercall which could allow a single PV guest to leak arbitrary amounts of memory, leading to a denial of service (bsc#1126192). - Fixed an issue which could allow malicious 64bit PV guests to cause a host crash (bsc#1127400). - Fixed an issue which could allow malicious or buggy x86 PV guest kernels to mount a Denial of Service attack affecting the whole system (bsc#1126197). - Fixed an issue which could allow an untrusted PV domain with access to a physical device to DMA into its own pagetables leading to privilege escalation (bsc#1126195). - Fixed an issue which could allow a malicious or buggy x86 PV guest kernels can mount a Denial of Service attack affecting the whole system (bsc#1126196).

Other issues addressed:

- Upstream bug fixes (bsc#1027519) - Fixed an issue where live migrations were failing when spectre was enabled on xen boot cmdline (bsc#1116380). - Fixed an issue where setup of grant_tables and other variables may fail (bsc#1126325). - Fixed a building issue (bsc#1119161). - Fixed an issue where xpti=no-dom0 was not working as expected (bsc#1105528). - Packages should no longer use /var/adm/fillup-templates (bsc#1069468). - Added Xen cmdline option 'suse_vtsc_tolerance' to avoid TSC emulation for HVM domUs (bsc#1026236).
Family:unixClass:patch
Status:Reference(s):1001203
1009026
1009085
1010395
1010401
1010402
1010404
1010410
1010422
1010427
1010517
1014437
1014441
1014442
1015941
1026236
1027282
1027519
1038395
1041090
1042670
1052916
1063671
1064392
1066471
1066472
1069468
1073269
1073748
1078326
1078485
1081750
1084650
1085416
1086001
1087240
1101644
1101645
1101651
1101656
1102682
1103203
1104918
1105323
1105528
1106812
1114988
1115040
1115045
1115047
1116380
1116708
1117756
1117963
1117964
1117965
1117966
1117967
1119161
1120507
1123157
1126140
1126141
1126192
1126195
1126196
1126197
1126198
1126201
1126325
1127400
1129346
1129623
1149792
1153830
1155094
1159035
1162224
1162367
1162825
1165894
1170411
1171561
929414
945401
961491
975299
982779
986675
991564
992549
994500
997833
CVE-2009-2285
CVE-2009-2347
CVE-2010-2065
CVE-2010-2067
CVE-2010-2233
CVE-2010-4665
CVE-2011-0192
CVE-2011-1167
CVE-2011-1526
CVE-2011-4862
CVE-2012-1173
CVE-2012-2113
CVE-2012-3401
CVE-2012-4564
CVE-2013-1960
CVE-2013-1961
CVE-2013-4231
CVE-2013-4232
CVE-2013-4243
CVE-2013-4244
CVE-2014-8127
CVE-2014-8128
CVE-2014-8129
CVE-2014-8130
CVE-2014-9655
CVE-2015-1547
CVE-2015-3622
CVE-2015-7554
CVE-2015-8781
CVE-2015-8782
CVE-2015-8783
CVE-2016-2123
CVE-2016-2125
CVE-2016-2126
CVE-2016-3186
CVE-2016-4008
CVE-2016-5285
CVE-2016-5290
CVE-2016-5291
CVE-2016-5296
CVE-2016-5297
CVE-2016-5314
CVE-2016-5316
CVE-2016-5317
CVE-2016-5320
CVE-2016-5875
CVE-2016-9064
CVE-2016-9066
CVE-2016-9074
CVE-2016-9957
CVE-2016-9958
CVE-2016-9959
CVE-2016-9960
CVE-2016-9961
CVE-2017-13080
CVE-2017-15649
CVE-2017-2885
CVE-2017-8386
CVE-2018-0886
CVE-2018-1000852
CVE-2018-10902
CVE-2018-19665
CVE-2018-19961
CVE-2018-19962
CVE-2018-19965
CVE-2018-19966
CVE-2018-19967
CVE-2018-2938
CVE-2018-2940
CVE-2018-2952
CVE-2018-2973
CVE-2018-3639
CVE-2018-5390
CVE-2018-8784
CVE-2018-8785
CVE-2018-8786
CVE-2018-8787
CVE-2018-8788
CVE-2018-8789
CVE-2019-18348
CVE-2019-6778
CVE-2019-9636
CVE-2019-9674
CVE-2019-9824
CVE-2020-8492
SUSE-SU-2016:1601-1
SUSE-SU-2016:3014-1
SUSE-SU-2016:3250-1
SUSE-SU-2016:3271-1
SUSE-SU-2016:3272-1
SUSE-SU-2017:1357-1
SUSE-SU-2017:2130-1
SUSE-SU-2017:3145-1
SUSE-SU-2018:3064-1
SUSE-SU-2019:0134-1
SUSE-SU-2019:0961-1
SUSE-SU-2020:1524-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
openSUSE Leap 15.1 NonFree
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND kdebase4-workspace-libs-4.11.22-lp150.7 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • ImageMagick-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-config-7-SUSE-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-config-7-upstream-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-devel-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-devel-32bit-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-doc-7.0.7.34-lp151.7.3 is installed
  • OR ImageMagick-extra-7.0.7.34-lp151.7.3 is installed
  • OR libMagick++-7_Q16HDRI4-7.0.7.34-lp151.7.3 is installed
  • OR libMagick++-7_Q16HDRI4-32bit-7.0.7.34-lp151.7.3 is installed
  • OR libMagick++-devel-7.0.7.34-lp151.7.3 is installed
  • OR libMagick++-devel-32bit-7.0.7.34-lp151.7.3 is installed
  • OR libMagickCore-7_Q16HDRI6-7.0.7.34-lp151.7.3 is installed
  • OR libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-lp151.7.3 is installed
  • OR libMagickWand-7_Q16HDRI6-7.0.7.34-lp151.7.3 is installed
  • OR libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-lp151.7.3 is installed
  • OR perl-PerlMagick-7.0.7.34-lp151.7.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 NonFree is installed
  • AND opera-67.0.3575.97-lp151.2.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • xen-4.9.4_02-3.50 is installed
  • OR xen-libs-4.9.4_02-3.50 is installed
  • OR xen-libs-32bit-4.9.4_02-3.50 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • freerdp-2.0.0~git.1463131968.4e66df7-12.8 is installed
  • OR libfreerdp2-2.0.0~git.1463131968.4e66df7-12.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • libgme-0.6.0-5 is installed
  • OR libgme0-0.6.0-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • libsoup-2.44.2-2.3 is installed
  • OR libsoup-2_4-1-2.44.2-2.3 is installed
  • OR libsoup-2_4-1-32bit-2.44.2-2.3 is installed
  • OR libsoup-lang-2.44.2-2.3 is installed
  • OR typelib-1_0-Soup-2_4-2.44.2-2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • krb5-appl-clients-1.0.3-1 is installed
  • OR krb5-appl-servers-1.0.3-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • cups-filters-1.0.58-15.2 is installed
  • OR cups-filters-cups-browsed-1.0.58-15.2 is installed
  • OR cups-filters-foomatic-rip-1.0.58-15.2 is installed
  • OR cups-filters-ghostscript-1.0.58-15.2 is installed
  • OR libqpdf18-7.1.1-3.3 is installed
  • OR qpdf-7.1.1-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kernel-firmware-20170530-21.22 is installed
  • OR ucode-amd-20170530-21.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • java-1_8_0-ibm-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-alsa-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-devel-1.8.0_sr5.15-30.33 is installed
  • OR java-1_8_0-ibm-plugin-1.8.0_sr5.15-30.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND apache2-mod_jk-1.2.40-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND xrdp-0.9.0~git.1456906198.f422461-21.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_180-94_103-default-4-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_28-4-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • python-PyYAML-5.1.2-26.9 is installed
  • OR python-asn1crypto-0.24.0-2.5 is installed
  • OR python-packaging-17.1-2.5 is installed
  • OR python3-PyYAML-5.1.2-26.9 is installed
  • OR python3-asn1crypto-0.24.0-2.5 is installed
  • OR python3-packaging-17.1-2.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • gnome-shell-search-provider-nautilus-3.20.3-23.6 is installed
  • OR libnautilus-extension1-3.20.3-23.6 is installed
  • OR nautilus-3.20.3-23.6 is installed
  • OR nautilus-lang-3.20.3-23.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND p7zip-9.20.1-7.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • java-1_8_0-openjdk-1.8.0.181-27.26 is installed
  • OR java-1_8_0-openjdk-demo-1.8.0.181-27.26 is installed
  • OR java-1_8_0-openjdk-devel-1.8.0.181-27.26 is installed
  • OR java-1_8_0-openjdk-headless-1.8.0.181-27.26 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • ardana-ansible-8.0+git.1583432621.24fa60e-3.70 is installed
  • OR ardana-barbican-8.0+git.1585152761.8ef3d61-4.33 is installed
  • OR ardana-db-8.0+git.1583944923.03cca6c-3.31 is installed
  • OR ardana-monasca-8.0+git.1583944894.38f023a-3.24 is installed
  • OR ardana-mq-8.0+git.1583944811.dc14403-3.19 is installed
  • OR ardana-neutron-8.0+git.1584715262.e4ea620-3.39 is installed
  • OR ardana-octavia-8.0+git.1585171918.418f5cf-3.26 is installed
  • OR ardana-tempest-8.0+git.1585311051.6ab5488-3.33 is installed
  • OR documentation-suse-openstack-cloud-installation-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-operations-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-opsconsole-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-planning-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-security-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-supplement-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-upstream-admin-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-upstream-user-8.20200319-1.23 is installed
  • OR documentation-suse-openstack-cloud-user-8.20200319-1.23 is installed
  • OR memcached-1.5.17-3.3 is installed
  • OR openstack-manila-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-api-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-data-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-doc-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-scheduler-5.1.1~dev5-3.26 is installed
  • OR openstack-manila-share-5.1.1~dev5-3.26 is installed
  • OR openstack-neutron-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-dhcp-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-doc-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-ha-tool-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-l3-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-linuxbridge-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-macvtap-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-metadata-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-metering-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-openvswitch-agent-11.0.9~dev63-3.30 is installed
  • OR openstack-neutron-server-11.0.9~dev63-3.30 is installed
  • OR openstack-nova-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-api-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-cells-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-compute-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-conductor-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-console-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-consoleauth-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-doc-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-novncproxy-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-placement-api-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-scheduler-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-serialproxy-16.1.9~dev61-3.35 is installed
  • OR openstack-nova-vncproxy-16.1.9~dev61-3.35 is installed
  • OR pdns-4.1.2-3.6 is installed
  • OR pdns-backend-mysql-4.1.2-3.6 is installed
  • OR python-amqp-2.4.2-3.9 is installed
  • OR python-manila-5.1.1~dev5-3.26 is installed
  • OR python-neutron-11.0.9~dev63-3.30 is installed
  • OR python-nova-16.1.9~dev61-3.35 is installed
  • OR venv-openstack-aodh-5.1.1~dev7-12.24 is installed
  • OR venv-openstack-aodh-x86_64-5.1.1~dev7-12.24 is installed
  • OR venv-openstack-barbican-5.0.2~dev3-12.25 is installed
  • OR venv-openstack-barbican-x86_64-5.0.2~dev3-12.25 is installed
  • OR venv-openstack-ceilometer-9.0.8~dev7-12.22 is installed
  • OR venv-openstack-ceilometer-x86_64-9.0.8~dev7-12.22 is installed
  • OR venv-openstack-cinder-11.2.3~dev23-14.25 is installed
  • OR venv-openstack-cinder-x86_64-11.2.3~dev23-14.25 is installed
  • OR venv-openstack-designate-5.0.3~dev7-12.23 is installed
  • OR venv-openstack-designate-x86_64-5.0.3~dev7-12.23 is installed
  • OR venv-openstack-freezer-5.0.0.0~xrc2~dev2-10.20 is installed
  • OR venv-openstack-freezer-x86_64-5.0.0.0~xrc2~dev2-10.20 is installed
  • OR venv-openstack-glance-15.0.3~dev3-12.23 is installed
  • OR venv-openstack-glance-x86_64-15.0.3~dev3-12.23 is installed
  • OR venv-openstack-heat-9.0.8~dev22-12.25 is installed
  • OR venv-openstack-heat-x86_64-9.0.8~dev22-12.25 is installed
  • OR venv-openstack-ironic-9.1.8~dev8-12.25 is installed
  • OR venv-openstack-ironic-x86_64-9.1.8~dev8-12.25 is installed
  • OR venv-openstack-keystone-12.0.4~dev5-11.26 is installed
  • OR venv-openstack-keystone-x86_64-12.0.4~dev5-11.26 is installed
  • OR venv-openstack-magnum-5.0.2_5.0.2_5.0.2~dev31-11.24 is installed
  • OR venv-openstack-magnum-x86_64-5.0.2_5.0.2_5.0.2~dev31-11.24 is installed
  • OR venv-openstack-manila-5.1.1~dev5-12.29 is installed
  • OR venv-openstack-manila-x86_64-5.1.1~dev5-12.29 is installed
  • OR venv-openstack-monasca-ceilometer-1.5.1_1.5.1_1.5.1~dev3-8.20 is installed
  • OR venv-openstack-monasca-ceilometer-x86_64-1.5.1_1.5.1_1.5.1~dev3-8.20 is installed
  • OR venv-openstack-murano-4.0.2~dev2-12.20 is installed
  • OR venv-openstack-murano-x86_64-4.0.2~dev2-12.20 is installed
  • OR venv-openstack-neutron-11.0.9~dev63-13.28 is installed
  • OR venv-openstack-neutron-x86_64-11.0.9~dev63-13.28 is installed
  • OR venv-openstack-nova-16.1.9~dev61-11.26 is installed
  • OR venv-openstack-nova-x86_64-16.1.9~dev61-11.26 is installed
  • OR venv-openstack-octavia-1.0.6~dev3-12.25 is installed
  • OR venv-openstack-octavia-x86_64-1.0.6~dev3-12.25 is installed
  • OR venv-openstack-sahara-7.0.5~dev4-11.24 is installed
  • OR venv-openstack-sahara-x86_64-7.0.5~dev4-11.24 is installed
  • OR venv-openstack-trove-8.0.2~dev2-11.24 is installed
  • OR venv-openstack-trove-x86_64-8.0.2~dev2-11.24 is installed
  • OR zookeeper-3.4.10-3.6 is installed
  • OR zookeeper-server-3.4.10-3.6 is installed
  • BACK