Oval Definition:oval:org.opensuse.security:def:59072
Revision Date:2020-12-01Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

Security vulnerabilities fixed:

- CVE-2018-19961, CVE-2018-19962: Fixed an issue related to insufficient TLB flushing with AMD IOMMUs, which potentially allowed a guest to escalate its privileges, may cause a Denial of Service (DoS) affecting the entire host, or may be able to access data it is not supposed to access. (XSA-275) (bsc#1115040) - CVE-2018-19965: Fixed an issue related to the INVPCID instruction in case non-canonical addresses are accessed, which may allow a guest to cause Xen to crash, resulting in a Denial of Service (DoS) affecting the entire host. (XSA-279) (bsc#1115045) - CVE-2018-19966: Fixed an issue related to a previous fix for XSA-240, which conflicted with shadow paging and allowed a guest to cause Xen to crash, resulting in a Denial of Service (DoS). (XSA-280) (bsc#1115047) - CVE-2018-19665: Fixed an integer overflow resulting in memory corruption in various Bluetooth functions, allowing this to crash qemu process resulting in Denial of Service (DoS). (bsc#1117756). - CVE-2018-18849: Fixed an out of bounds memory access in the LSI53C895A SCSI host bus adapter emulation, which allowed a user and/or process to crash the qemu process resulting in a Denial of Service (DoS). (bsc#1114423)

Other bugs fixed:

- Fixed an issue related to a domU hang on SLE12-SP3 HV (bsc#1108940) - Fixed an issue with xpti=no-dom0 not working as expected (bsc#1105528) - Fixed an issue with live migrations, which used to fail when spectre is enabled on xen boot cmdline (bsc#1116380) - Upstream bug fixes (bsc#1027519)
Family:unixClass:patch
Status:Reference(s):1027519
1091836
1105528
1107832
1108940
1110233
1114423
1115040
1115045
1115047
1116380
1117756
1124729
1124734
1128378
1132728
1132729
1132732
1132734
1134718
1149294
1149295
1149296
1149297
1149298
1149299
1149303
1149304
1149324
1153108
1155787
1156321
1156331
1157770
1157888
1158003
1158004
1158005
1158006
1158007
1161181
1165631
1167068
1167152
1168140
1168142
1169392
1170558
1171363
1172205
1172906
1172935
1173197
1173369
1173580
1173659
1173942
1174247
682920
CVE-2010-0624
CVE-2011-3146
CVE-2013-1881
CVE-2016-6321
CVE-2017-2518
CVE-2018-14633
CVE-2018-17182
CVE-2018-18849
CVE-2018-19665
CVE-2018-19961
CVE-2018-19962
CVE-2018-19965
CVE-2018-19966
CVE-2018-20856
CVE-2019-10220
CVE-2019-10245
CVE-2019-11740
CVE-2019-11742
CVE-2019-11743
CVE-2019-11744
CVE-2019-11746
CVE-2019-11752
CVE-2019-11753
CVE-2019-13272
CVE-2019-16746
CVE-2019-19577
CVE-2019-19578
CVE-2019-19579
CVE-2019-19580
CVE-2019-19581
CVE-2019-19583
CVE-2019-2602
CVE-2019-2684
CVE-2019-2697
CVE-2019-2698
CVE-2019-6974
CVE-2019-7221
CVE-2019-9213
CVE-2019-9812
CVE-2020-0543
CVE-2020-11668
CVE-2020-11739
CVE-2020-11740
CVE-2020-11741
CVE-2020-11742
CVE-2020-12108
CVE-2020-12137
CVE-2020-14093
CVE-2020-14154
CVE-2020-14331
CVE-2020-14954
CVE-2020-15011
CVE-2020-1749
CVE-2020-4044
CVE-2020-7211
SUSE-SU-2018:1661-2
SUSE-SU-2019:0020-1
SUSE-SU-2019:1644-1
SUSE-SU-2019:2436-1
SUSE-SU-2020:1301-1
SUSE-SU-2020:1630-1
SUSE-SU-2020:1991-1
SUSE-SU-2020:2048-1
SUSE-SU-2020:2502-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • avahi-0.6.32-lp150.3 is installed
  • OR avahi-lang-0.6.32-lp150.3 is installed
  • OR libavahi-client3-0.6.32-lp150.3 is installed
  • OR libavahi-common3-0.6.32-lp150.3 is installed
  • OR libavahi-core7-0.6.32-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • qemu-3.1.1-lp151.7.3 is installed
  • OR qemu-arm-3.1.1-lp151.7.3 is installed
  • OR qemu-audio-alsa-3.1.1-lp151.7.3 is installed
  • OR qemu-audio-oss-3.1.1-lp151.7.3 is installed
  • OR qemu-audio-pa-3.1.1-lp151.7.3 is installed
  • OR qemu-audio-sdl-3.1.1-lp151.7.3 is installed
  • OR qemu-block-curl-3.1.1-lp151.7.3 is installed
  • OR qemu-block-dmg-3.1.1-lp151.7.3 is installed
  • OR qemu-block-gluster-3.1.1-lp151.7.3 is installed
  • OR qemu-block-iscsi-3.1.1-lp151.7.3 is installed
  • OR qemu-block-nfs-3.1.1-lp151.7.3 is installed
  • OR qemu-block-rbd-3.1.1-lp151.7.3 is installed
  • OR qemu-block-ssh-3.1.1-lp151.7.3 is installed
  • OR qemu-extra-3.1.1-lp151.7.3 is installed
  • OR qemu-guest-agent-3.1.1-lp151.7.3 is installed
  • OR qemu-ipxe-1.0.0+-lp151.7.3 is installed
  • OR qemu-ksm-3.1.1-lp151.7.3 is installed
  • OR qemu-kvm-3.1.1-lp151.7.3 is installed
  • OR qemu-lang-3.1.1-lp151.7.3 is installed
  • OR qemu-linux-user-3.1.1-lp151.7.3 is installed
  • OR qemu-ppc-3.1.1-lp151.7.3 is installed
  • OR qemu-s390-3.1.1-lp151.7.3 is installed
  • OR qemu-seabios-1.12.0-lp151.7.3 is installed
  • OR qemu-sgabios-8-lp151.7.3 is installed
  • OR qemu-testsuite-3.1.1-lp151.7.3 is installed
  • OR qemu-tools-3.1.1-lp151.7.3 is installed
  • OR qemu-ui-curses-3.1.1-lp151.7.3 is installed
  • OR qemu-ui-gtk-3.1.1-lp151.7.3 is installed
  • OR qemu-ui-sdl-3.1.1-lp151.7.3 is installed
  • OR qemu-vgabios-1.12.0-lp151.7.3 is installed
  • OR qemu-x86-3.1.1-lp151.7.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20180425-13.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_103-92_56-default-10-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_17-10-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • xen-4.7.6_05-43.45 is installed
  • OR xen-doc-html-4.7.6_05-43.45 is installed
  • OR xen-libs-4.7.6_05-43.45 is installed
  • OR xen-libs-32bit-4.7.6_05-43.45 is installed
  • OR xen-tools-4.7.6_05-43.45 is installed
  • OR xen-tools-domU-4.7.6_05-43.45 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • gdk-pixbuf-loader-rsvg-2.40.15-4 is installed
  • OR librsvg-2-2-2.40.15-4 is installed
  • OR librsvg-2-2-32bit-2.40.15-4 is installed
  • OR rsvg-view-2.40.15-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • kernel-default-4.4.180-94.107 is installed
  • OR kernel-default-base-4.4.180-94.107 is installed
  • OR kernel-default-devel-4.4.180-94.107 is installed
  • OR kernel-devel-4.4.180-94.107 is installed
  • OR kernel-macros-4.4.180-94.107 is installed
  • OR kernel-source-4.4.180-94.107 is installed
  • OR kernel-syms-4.4.180-94.107 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND mailman-2.1.17-3.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libseccomp-2.4.1-11.3 is installed
  • OR libseccomp2-2.4.1-11.3 is installed
  • OR libseccomp2-32bit-2.4.1-11.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.30-38.26 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.30-38.26 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • evince-3.20.2-6.22 is installed
  • OR evince-browser-plugin-3.20.2-6.22 is installed
  • OR evince-lang-3.20.2-6.22 is installed
  • OR evince-plugin-djvudocument-3.20.2-6.22 is installed
  • OR evince-plugin-dvidocument-3.20.2-6.22 is installed
  • OR evince-plugin-pdfdocument-3.20.2-6.22 is installed
  • OR evince-plugin-psdocument-3.20.2-6.22 is installed
  • OR evince-plugin-tiffdocument-3.20.2-6.22 is installed
  • OR evince-plugin-xpsdocument-3.20.2-6.22 is installed
  • OR libevdocument3-4-3.20.2-6.22 is installed
  • OR libevview3-3-3.20.2-6.22 is installed
  • OR nautilus-evince-3.20.2-6.22 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • xen-4.9.4_06-3.62 is installed
  • OR xen-doc-html-4.9.4_06-3.62 is installed
  • OR xen-libs-4.9.4_06-3.62 is installed
  • OR xen-libs-32bit-4.9.4_06-3.62 is installed
  • OR xen-tools-4.9.4_06-3.62 is installed
  • OR xen-tools-domU-4.9.4_06-3.62 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.14 is installed
  • OR libssh2-1-32bit-1.4.3-20.14 is installed
  • OR libssh2_org-1.4.3-20.14 is installed
  • BACK