Oval Definition:oval:org.opensuse.security:def:70475
Revision Date:2021-09-02Version:1
Title:Security update for xen (Important)
Description:

This update for xen fixes the following issues:

Security issues fixed:

- CVE-2021-28693: xen/arm: Boot modules are not scrubbed (bsc#1186428) - CVE-2021-28692: xen: inappropriate x86 IOMMU timeout detection / handling (bsc#1186429) - CVE-2021-0089: xen: Speculative Code Store Bypass (bsc#1186433) - CVE-2021-28690: xen: x86: TSX Async Abort protections not restored after S3 (bsc#1186434)

- CVE-2021-28694,CVE-2021-28695,CVE-2021-28696: IOMMU page mapping issues on x86 (XSA-378)(bsc#1189373). - CVE-2021-28697: grant table v2 status pages may remain accessible after de-allocation (XSA-379)(bsc#1189376). - CVE-2021-28698: long running loops in grant table handling (XSA-380)(bsc#1189378). - CVE-2021-28699: inadequate grant-v2 status frames array bounds check (XSA-382)(bsc#1189380). - CVE-2021-28700: No memory limit for dom0less domUs (XSA-383)(bsc#1189381).

Other issues fixed:

- Fixed 'Panic on CPU 0: IO-APIC + timer doesn't work!' (bsc#1180491) - Upstream bug fixes (bsc#1027519) - Dom0 hangs when pinning CPUs for dom0 with HVM guest (bsc#1179246). - Fixed Xen SLES11SP4 guest hangs on cluster (bsc#1188050). - Fixed PVHVM SLES12 SP5 - NMI Watchdog CPU Stuck (bsc#1180846). - Core cannot be opened when using xl dump-core of VM with PTF (bsc#1183243). - Prevent superpage allocation in the LAPIC and ACPI_INFO range (bsc#1189882).
Family:unixClass:patch
Status:Reference(s):1027519
1166751
1174628
1177895
1179148
1179246
1180491
1180846
1181989
1183243
1186428
1186429
1186433
1186434
1188050
1189373
1189376
1189378
1189380
1189381
1189882
CVE-2020-0556
CVE-2020-14344
CVE-2020-27153
CVE-2021-0089
CVE-2021-28690
CVE-2021-28692
CVE-2021-28693
CVE-2021-28694
CVE-2021-28695
CVE-2021-28696
CVE-2021-28697
CVE-2021-28698
CVE-2021-28699
CVE-2021-28700
SUSE-SU-2020:3034-1
SUSE-SU-2021:2925-1
Platform(s):SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • bluez-5.48-13.3 is installed
  • OR bluez-devel-5.48-13.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • libX11-1.6.5-3.6 is installed
  • OR libX11-devel-32bit-1.6.5-3.6 is installed
  • OR libxcb-1.13-3.5 is installed
  • OR libxcb-composite0-32bit-1.13-3.5 is installed
  • OR libxcb-damage0-32bit-1.13-3.5 is installed
  • OR libxcb-devel-32bit-1.13-3.5 is installed
  • OR libxcb-dpms0-32bit-1.13-3.5 is installed
  • OR libxcb-randr0-32bit-1.13-3.5 is installed
  • OR libxcb-record0-32bit-1.13-3.5 is installed
  • OR libxcb-res0-32bit-1.13-3.5 is installed
  • OR libxcb-screensaver0-32bit-1.13-3.5 is installed
  • OR libxcb-shape0-32bit-1.13-3.5 is installed
  • OR libxcb-xf86dri0-32bit-1.13-3.5 is installed
  • OR libxcb-xinerama0-32bit-1.13-3.5 is installed
  • OR libxcb-xinput0-32bit-1.13-3.5 is installed
  • OR libxcb-xkb1-32bit-1.13-3.5 is installed
  • OR libxcb-xtest0-32bit-1.13-3.5 is installed
  • OR libxcb-xv0-32bit-1.13-3.5 is installed
  • OR libxcb-xvmc0-32bit-1.13-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • AND Package Information
  • xen-4.12.4_12-3.52.1 is installed
  • OR xen-devel-4.12.4_12-3.52.1 is installed
  • OR xen-libs-4.12.4_12-3.52.1 is installed
  • OR xen-tools-4.12.4_12-3.52.1 is installed
  • OR xen-tools-domU-4.12.4_12-3.52.1 is installed
  • BACK