Oval Definition:oval:org.opensuse.security:def:58140
Revision Date:2020-12-01Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

Security vulnerabilities fixed:

- CVE-2018-19961, CVE-2018-19962: Fixed an issue related to insufficient TLB flushing with AMD IOMMUs, which potentially allowed a guest to escalate its privileges, may cause a Denial of Service (DoS) affecting the entire host, or may be able to access data it is not supposed to access. (XSA-275) (bsc#1115040) - CVE-2018-19965: Fixed an issue related to the INVPCID instruction in case non-canonical addresses are accessed, which may allow a guest to cause Xen to crash, resulting in a Denial of Service (DoS) affecting the entire host. (XSA-279) (bsc#1115045) - CVE-2018-19966: Fixed an issue related to a previous fix for XSA-240, which conflicted with shadow paging and allowed a guest to cause Xen to crash, resulting in a Denial of Service (DoS). (XSA-280) (bsc#1115047) - CVE-2018-19665: Fixed an integer overflow resulting in memory corruption in various Bluetooth functions, allowing this to crash qemu process resulting in Denial of Service (DoS). (bsc#1117756). - CVE-2018-18849: Fixed an out of bounds memory access in the LSI53C895A SCSI host bus adapter emulation, which allowed a user and/or process to crash the qemu process resulting in a Denial of Service (DoS). (bsc#1114423)

Other bugs fixed:

- Fixed an issue related to a domU hang on SLE12-SP3 HV (bsc#1108940) - Fixed an issue with xpti=no-dom0 not working as expected (bsc#1105528) - Fixed an issue with live migrations, which used to fail when spectre is enabled on xen boot cmdline (bsc#1116380) - Upstream bug fixes (bsc#1027519)
Family:unixClass:patch
Status:Reference(s):1005091
1012382
1012677
1024908
1027519
1034113
1043485
1055478
1062645
1068032
1070737
1073311
1079152
1080157
1080533
1082632
1082962
1083650
1083900
1085185
1086400
1087007
1087012
1087036
1087086
1087095
1087231
1087659
1087906
1089895
1090534
1090955
1092497
1092552
1092813
1092904
1093158
1094033
1094268
1094353
1094823
1095042
1096140
1096242
1096281
1096728
1096748
1097158
1097356
1097624
1098592
1100152
1101820
1103186
1104199
1104202
1105528
1106913
1108940
1109772
1111331
1111657
1112178
1113399
1114423
1115040
1115045
1115047
1116380
1116841
1117756
1118338
1119019
1120374
1122822
1122983
1124832
1125580
1129279
1130324
1131416
1131427
1131587
1132673
1132828
1133188
1138748
1139073
1141035
1149792
1154043
1154824
1155988
1158328
1164871
1171098
1171195
1171202
1171218
1171219
1171689
1171698
1172221
1172317
1172515
1176315
1178171
945190
967970
973378
975500
981848
995964
CVE-2014-3577
CVE-2015-5262
CVE-2016-2533
CVE-2016-4009
CVE-2016-7098
CVE-2016-8636
CVE-2017-13305
CVE-2017-15191
CVE-2017-15192
CVE-2017-15193
CVE-2017-17741
CVE-2017-18174
CVE-2017-18241
CVE-2017-18249
CVE-2018-0732
CVE-2018-1000199
CVE-2018-1000204
CVE-2018-1065
CVE-2018-10903
CVE-2018-1091
CVE-2018-10915
CVE-2018-1092
CVE-2018-10925
CVE-2018-1093
CVE-2018-1094
CVE-2018-1120
CVE-2018-1128
CVE-2018-1129
CVE-2018-1130
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-18500
CVE-2018-18501
CVE-2018-18505
CVE-2018-18849
CVE-2018-19407
CVE-2018-19665
CVE-2018-19961
CVE-2018-19962
CVE-2018-19965
CVE-2018-19966
CVE-2018-3665
CVE-2018-5803
CVE-2018-5848
CVE-2018-7492
CVE-2019-11091
CVE-2019-11135
CVE-2019-11139
CVE-2019-11486
CVE-2019-11745
CVE-2019-13722
CVE-2019-17005
CVE-2019-17008
CVE-2019-17009
CVE-2019-17010
CVE-2019-17011
CVE-2019-17012
CVE-2019-3882
CVE-2019-8564
CVE-2019-9503
CVE-2019-9924
CVE-2020-0543
CVE-2020-10757
CVE-2020-12114
CVE-2020-12652
CVE-2020-12653
CVE-2020-12654
CVE-2020-12656
CVE-2020-17507
SUSE-SU-2016:3268-1
SUSE-SU-2017:2860-1
SUSE-SU-2018:3377-1
SUSE-SU-2019:0020-1
SUSE-SU-2019:0336-1
SUSE-SU-2019:0838-2
SUSE-SU-2019:1287-1
SUSE-SU-2019:2334-1
SUSE-SU-2019:2959-1
SUSE-SU-2019:3347-1
SUSE-SU-2020:0792-1
SUSE-SU-2020:1597-1
SUSE-SU-2020:2760-1
SUSE-SU-2020:3149-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libssh4-0.7.5-lp150.4 is installed
  • OR libssh4-32bit-0.7.5-lp150.4 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • ceph-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-base-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-common-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-dashboard-e2e-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-fuse-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-grafana-dashboards-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mds-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-dashboard-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-diskprediction-cloud-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-diskprediction-local-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-k8sevents-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-rook-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mgr-ssh-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-mon-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-osd-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-prometheus-alerts-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-radosgw-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-resource-agents-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR ceph-test-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR cephfs-shell-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR libcephfs-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR libcephfs2-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librados-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librados2-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR libradospp-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR libradosstriper-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR libradosstriper1-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librbd-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librbd1-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librgw-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR librgw2-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR python3-ceph-argparse-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR python3-cephfs-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR python3-rados-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR python3-rbd-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR python3-rgw-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR rados-objclass-devel-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR rbd-fuse-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR rbd-mirror-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • OR rbd-nbd-14.2.5.382+g8881d33957-lp151.2.10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND wget-1.14-17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • MozillaFirefox-60.5.0esr-109.58 is installed
  • OR MozillaFirefox-branding-SLE-60-32.5 is installed
  • OR MozillaFirefox-devel-60.5.0esr-109.58 is installed
  • OR MozillaFirefox-translations-common-60.5.0esr-109.58 is installed
  • OR libfreebl3-3.41.1-58.25 is installed
  • OR libfreebl3-32bit-3.41.1-58.25 is installed
  • OR libfreebl3-hmac-3.41.1-58.25 is installed
  • OR libfreebl3-hmac-32bit-3.41.1-58.25 is installed
  • OR libsoftokn3-3.41.1-58.25 is installed
  • OR libsoftokn3-32bit-3.41.1-58.25 is installed
  • OR libsoftokn3-hmac-3.41.1-58.25 is installed
  • OR libsoftokn3-hmac-32bit-3.41.1-58.25 is installed
  • OR mozilla-nss-3.41.1-58.25 is installed
  • OR mozilla-nss-32bit-3.41.1-58.25 is installed
  • OR mozilla-nss-certs-3.41.1-58.25 is installed
  • OR mozilla-nss-certs-32bit-3.41.1-58.25 is installed
  • OR mozilla-nss-sysinit-3.41.1-58.25 is installed
  • OR mozilla-nss-sysinit-32bit-3.41.1-58.25 is installed
  • OR mozilla-nss-tools-3.41.1-58.25 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kernel-default-4.4.121-92.85 is installed
  • OR kernel-default-base-4.4.121-92.85 is installed
  • OR kernel-default-devel-4.4.121-92.85 is installed
  • OR kernel-devel-4.4.121-92.85 is installed
  • OR kernel-macros-4.4.121-92.85 is installed
  • OR kernel-source-4.4.121-92.85 is installed
  • OR kernel-syms-4.4.121-92.85 is installed
  • OR kgraft-patch-4_4_121-92_85-default-1-3.5 is installed
  • OR kgraft-patch-SLE12-SP2_Update_23-1-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • postgresql96-9.6.10-3.22 is installed
  • OR postgresql96-contrib-9.6.10-3.22 is installed
  • OR postgresql96-docs-9.6.10-3.22 is installed
  • OR postgresql96-libs-9.6.10-3.22 is installed
  • OR postgresql96-server-9.6.10-3.22 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND clamav-0.99.2-32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • ibus-1.5.13-15.11 is installed
  • OR ibus-gtk-1.5.13-15.11 is installed
  • OR ibus-gtk3-1.5.13-15.11 is installed
  • OR ibus-lang-1.5.13-15.11 is installed
  • OR libibus-1_0-5-1.5.13-15.11 is installed
  • OR typelib-1_0-IBus-1_0-1.5.13-15.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • ghostscript-9.27-23.31 is installed
  • OR ghostscript-x11-9.27-23.31 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_143-94_47-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_16-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.50-38.41 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.50-38.41 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.50-38.41 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.50-38.41 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND busybox-1.21.1-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • xen-4.7.6_05-43.45 is installed
  • OR xen-doc-html-4.7.6_05-43.45 is installed
  • OR xen-libs-4.7.6_05-43.45 is installed
  • OR xen-libs-32bit-4.7.6_05-43.45 is installed
  • OR xen-tools-4.7.6_05-43.45 is installed
  • OR xen-tools-domU-4.7.6_05-43.45 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND slf4j-1.7.12-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND slf4j-1.7.12-3.3 is installed
  • BACK