Oval Definition:oval:org.opensuse.security:def:63826
Revision Date:2020-12-01Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

- CVE-2018-12207: Untrusted virtual machines on Intel CPUs could exploit a race condition in the Instruction Fetch Unit of the Intel CPU to cause a Machine Exception during Page Size Change, causing the CPU core to be non-functional. (bsc#1155945) - CVE-2019-11135: Aborting an asynchronous TSX operation on Intel CPUs with Transactional Memory support could be used to facilitate sidechannel information leaks out of microarchitectural buffers, similar to the previously described 'Microarchitectural Data Sampling' attack. (bsc#1152497). - CVE-2019-18424: An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. (bsc#1154461). - CVE-2019-18421: A malicious PV guest administrator may have been able to escalate their privilege to that of the host. (bsc#1154458). - CVE-2019-18425: 32-bit PV guest user mode could elevate its privileges to that of the guest kernel. (bsc#1154456). - CVE-2019-18420: Malicious x86 PV guests may have caused a hypervisor crash, resulting in a Denial of Service (Dos). (bsc#1154448)
Family:unixClass:patch
Status:Reference(s):1046303
1050244
1051510
1051858
1061840
1065600
1065729
1071995
1085030
1086301
1086313
1086314
1088810
1092100
1104427
1105392
1111666
1112178
1112504
1114279
1118338
1121753
1123328
1127371
1133021
1133147
1134973
1138872
1140025
1143959
1144333
1150011
1151585
1151910
1151927
1152497
1153917
1154243
1154448
1154456
1154458
1154461
1155331
1155334
1155945
1156259
1156286
1156462
1157155
1157157
1157303
1157424
1157692
1157853
1157966
1158013
1158021
1158026
1158533
1158819
1159028
1159271
1159297
1159394
1159483
1159484
1159569
1159588
1159841
1159856
1159858
1159860
1159908
1159909
1159910
1159911
1159955
1160195
1160210
1160211
1160218
1160249
1160250
1160251
1160433
1160442
1160476
1160560
1160755
1160756
1160784
1160787
1160802
1160803
1160804
1160917
1160937
1160966
1160979
1161087
1161360
1161514
1161518
1161522
1161523
1161549
1161552
1161674
1161702
1161875
1161907
1161931
1161933
1161934
1161935
1161936
1161937
1162028
1162067
1162109
1162139
1162557
1162617
1162618
1162619
1162623
1162928
1162943
1163383
1163384
1163762
1163774
1163836
1163840
1163841
1163842
1163843
1163844
1163845
1163846
1163849
1163850
1163851
1163852
1163853
1163855
1163856
1163857
1163858
1163859
1163860
1163861
1163862
1163863
1163867
1163869
1163880
1163971
1164069
1164098
1164115
1164314
1164315
1164388
1164471
1164572
1164574
1164632
1164705
1164712
1164727
1164728
1164729
1164730
1164731
1164732
1164733
1164734
1164735
1165680
1169952
1171437
1172307
1173159
1173160
1173161
1173359
1176437
1177950
1178591
CVE-2018-1122
CVE-2018-1123
CVE-2018-1124
CVE-2018-1125
CVE-2018-1126
CVE-2018-12207
CVE-2019-11135
CVE-2019-11708
CVE-2019-14615
CVE-2019-14822
CVE-2019-14896
CVE-2019-14897
CVE-2019-15691
CVE-2019-15692
CVE-2019-15693
CVE-2019-15694
CVE-2019-15695
CVE-2019-16680
CVE-2019-16994
CVE-2019-18420
CVE-2019-18421
CVE-2019-18424
CVE-2019-18425
CVE-2019-18808
CVE-2019-19036
CVE-2019-19045
CVE-2019-19054
CVE-2019-19066
CVE-2019-19318
CVE-2019-19319
CVE-2019-19447
CVE-2019-19767
CVE-2019-19965
CVE-2019-19966
CVE-2019-20054
CVE-2019-20095
CVE-2019-20096
CVE-2020-10730
CVE-2020-10745
CVE-2020-10760
CVE-2020-14303
CVE-2020-2732
CVE-2020-28368
CVE-2020-6097
CVE-2020-7053
CVE-2020-8428
CVE-2020-8648
CVE-2020-8992
CVE-2020-9272
CVE-2020-9273
openSUSE-SU-2019:1595-1
openSUSE-SU-2019:2199-1
openSUSE-SU-2020:0273-1
openSUSE-SU-2020:0984-1
openSUSE-SU-2020:1736-1
SUSE-SU-2019:0450-1
SUSE-SU-2019:2962-1
SUSE-SU-2020:0559-1
SUSE-SU-2020:1088-1
SUSE-SU-2020:1749-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • MozillaFirefox-60.7.2-lp151.2.7 is installed
  • OR MozillaFirefox-branding-upstream-60.7.2-lp151.2.7 is installed
  • OR MozillaFirefox-buildsymbols-60.7.2-lp151.2.7 is installed
  • OR MozillaFirefox-devel-60.7.2-lp151.2.7 is installed
  • OR MozillaFirefox-translations-common-60.7.2-lp151.2.7 is installed
  • OR MozillaFirefox-translations-other-60.7.2-lp151.2.7 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND atftp-0.7.2-lp152.2.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • xen-4.11.2_04-2.17 is installed
  • OR xen-doc-html-4.11.2_04-2.17 is installed
  • OR xen-libs-4.11.2_04-2.17 is installed
  • OR xen-libs-32bit-4.11.2_04-2.17 is installed
  • OR xen-tools-4.11.2_04-2.17 is installed
  • OR xen-tools-domU-4.11.2_04-2.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • xen-4.11.4_12-2.42 is installed
  • OR xen-doc-html-4.11.4_12-2.42 is installed
  • OR xen-libs-4.11.4_12-2.42 is installed
  • OR xen-libs-32bit-4.11.4_12-2.42 is installed
  • OR xen-tools-4.11.4_12-2.42 is installed
  • OR xen-tools-domU-4.11.4_12-2.42 is installed
  • BACK