SUSE Security Update: Security update for xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2017:1145-1
Rating: important
References: #1028655 #1029827 #1030144 #1034843 #1034844
#1034845 #1034994 #1035483
Cross-References: CVE-2016-9603 CVE-2017-7718 CVE-2017-7980
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP4
______________________________________________________________________________
An update that solves three vulnerabilities and has 5 fixes
is now available.
Description:
This update for xen fixes several issues.
These security issues were fixed:
– A malicious 64-bit PV guest may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks by placing a IRET hypercall in the middle of a multicall batch
(XSA-213, bsc#1034843)
– A malicious pair of guests may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks because of a missing check when transfering pages via
GNTTABOP_transfer (XSA-214, bsc#1034844).
– CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS
privileged users to cause a denial of service (out-of-bounds read and
QEMU process crash) via vectors related to copying VGA data via the
cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions
(bsc#1034994).
– CVE-2016-9603: A privileged user within the guest VM could have caused a
heap overflow in the device model process, potentially escalating their
privileges to that of the device model process (bsc#1028655)
These non-security issues were fixed:
– bsc#1029827: Additional xenstore patch
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
– SUSE Linux Enterprise Software Development Kit 11-SP4:
zypper in -t patch sdksp4-xen-13084=1
– SUSE Linux Enterprise Server 11-SP4:
zypper in -t patch slessp4-xen-13084=1
– SUSE Linux Enterprise Debuginfo 11-SP4:
zypper in -t patch dbgsp4-xen-13084=1
To bring your system up-to-date, use “zypper patch”.
Package List:
– SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64):
xen-devel-4.4.4_18-57.1
– SUSE Linux Enterprise Server 11-SP4 (i586 x86_64):
xen-kmp-default-4.4.4_18_3.0.101_97-57.1
xen-libs-4.4.4_18-57.1
xen-tools-domU-4.4.4_18-57.1
– SUSE Linux Enterprise Server 11-SP4 (x86_64):
xen-4.4.4_18-57.1
xen-doc-html-4.4.4_18-57.1
xen-libs-32bit-4.4.4_18-57.1
xen-tools-4.4.4_18-57.1
– SUSE Linux Enterprise Server 11-SP4 (i586):
xen-kmp-pae-4.4.4_18_3.0.101_97-57.1
– SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64):
xen-debuginfo-4.4.4_18-57.1
xen-debugsource-4.4.4_18-57.1
References:
https://www.suse.com/security/cve/CVE-2016-9603.html
https://www.suse.com/security/cve/CVE-2017-7718.html
https://www.suse.com/security/cve/CVE-2017-7980.html
https://bugzilla.suse.com/1028655
https://bugzilla.suse.com/1029827
https://bugzilla.suse.com/1030144
https://bugzilla.suse.com/1034843
https://bugzilla.suse.com/1034844
https://bugzilla.suse.com/1034845
https://bugzilla.suse.com/1034994
https://bugzilla.suse.com/1035483
—
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
SUSE Security Update: Security update for xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2017:1147-1
Rating: important
References: #1015348 #1022555 #1026636 #1027519 #1027570
#1028235 #1028655 #1029827 #1030144 #1030442
#1034843 #1034844 #1034845 #1034994 #1035483
Cross-References: CVE-2016-9603 CVE-2017-2633 CVE-2017-6414
CVE-2017-6505 CVE-2017-7718 CVE-2017-7980
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP1
SUSE Linux Enterprise Server 12-SP1
SUSE Linux Enterprise Desktop 12-SP1
______________________________________________________________________________
An update that solves 6 vulnerabilities and has 9 fixes is
now available.
Description:
This update for xen fixes several issues.
These security issues were fixed:
– A malicious 64-bit PV guest may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks by placing a IRET hypercall in the middle of a multicall batch
(XSA-213, bsc#1034843)
– A malicious pair of guests may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks because of a missing check when transfering pages via
GNTTABOP_transfer (XSA-214, bsc#1034844).
– CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS
privileged users to cause a denial of service (out-of-bounds read and
QEMU process crash) via vectors related to copying VGA data via the
cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions
(bsc#1034994).
– CVE-2016-9603: A privileged user within the guest VM could have caused a
heap overflow in the device model process, potentially escalating their
privileges to that of the device model process (bsc#1028655)
These non-security issues were fixed:
– bsc#1027519: Missing upstream bug fixes
– bsc#1015348: libvirtd does not start during boot
– bsc#1022555: Timeout in “execution of /etc/xen/scripts/block add
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
– SUSE Linux Enterprise Software Development Kit 12-SP1:
zypper in -t patch SUSE-SLE-SDK-12-SP1-2017-661=1
– SUSE Linux Enterprise Server 12-SP1:
zypper in -t patch SUSE-SLE-SERVER-12-SP1-2017-661=1
– SUSE Linux Enterprise Desktop 12-SP1:
zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2017-661=1
To bring your system up-to-date, use “zypper patch”.
Package List:
– SUSE Linux Enterprise Software Development Kit 12-SP1 (x86_64):
xen-debugsource-4.5.5_10-22.14.1
xen-devel-4.5.5_10-22.14.1
– SUSE Linux Enterprise Server 12-SP1 (x86_64):
xen-4.5.5_10-22.14.1
xen-debugsource-4.5.5_10-22.14.1
xen-doc-html-4.5.5_10-22.14.1
xen-kmp-default-4.5.5_10_k3.12.69_60.64.35-22.14.1
xen-kmp-default-debuginfo-4.5.5_10_k3.12.69_60.64.35-22.14.1
xen-libs-32bit-4.5.5_10-22.14.1
xen-libs-4.5.5_10-22.14.1
xen-libs-debuginfo-32bit-4.5.5_10-22.14.1
xen-libs-debuginfo-4.5.5_10-22.14.1
xen-tools-4.5.5_10-22.14.1
xen-tools-debuginfo-4.5.5_10-22.14.1
xen-tools-domU-4.5.5_10-22.14.1
xen-tools-domU-debuginfo-4.5.5_10-22.14.1
– SUSE Linux Enterprise Desktop 12-SP1 (x86_64):
xen-4.5.5_10-22.14.1
xen-debugsource-4.5.5_10-22.14.1
xen-kmp-default-4.5.5_10_k3.12.69_60.64.35-22.14.1
xen-kmp-default-debuginfo-4.5.5_10_k3.12.69_60.64.35-22.14.1
xen-libs-32bit-4.5.5_10-22.14.1
xen-libs-4.5.5_10-22.14.1
xen-libs-debuginfo-32bit-4.5.5_10-22.14.1
xen-libs-debuginfo-4.5.5_10-22.14.1
References:
https://www.suse.com/security/cve/CVE-2016-9603.html
https://www.suse.com/security/cve/CVE-2017-2633.html
https://www.suse.com/security/cve/CVE-2017-6414.html
https://www.suse.com/security/cve/CVE-2017-6505.html
https://www.suse.com/security/cve/CVE-2017-7718.html
https://www.suse.com/security/cve/CVE-2017-7980.html
https://bugzilla.suse.com/1015348
https://bugzilla.suse.com/1022555
https://bugzilla.suse.com/1026636
https://bugzilla.suse.com/1027519
https://bugzilla.suse.com/1027570
https://bugzilla.suse.com/1028235
https://bugzilla.suse.com/1028655
https://bugzilla.suse.com/1029827
https://bugzilla.suse.com/1030144
https://bugzilla.suse.com/1030442
https://bugzilla.suse.com/1034843
https://bugzilla.suse.com/1034844
https://bugzilla.suse.com/1034845
https://bugzilla.suse.com/1034994
https://bugzilla.suse.com/1035483
–
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
SUSE Security Update: Security update for xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2017:1143-1
Rating: important
References: #1022703 #1028655 #1029827 #1030144 #1034843
#1034844 #1034994 #1036146
Cross-References: CVE-2016-9603 CVE-2017-7718
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP2
SUSE Linux Enterprise Server 12-SP2
SUSE Linux Enterprise Desktop 12-SP2
______________________________________________________________________________
An update that solves two vulnerabilities and has 6 fixes
is now available.
Description:
This update for xen fixes several issues.
These security issues were fixed:
– A malicious 64-bit PV guest may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks by placing a IRET hypercall in the middle of a multicall batch
(XSA-213, bsc#1034843)
– A malicious pair of guests may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks because of a missing check when transfering pages via
GNTTABOP_transfer (XSA-214, bsc#1034844).
– CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS
privileged users to cause a denial of service (out-of-bounds read and
QEMU process crash) via vectors related to copying VGA data via the
cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions
(bsc#1034994).
– CVE-2016-9603: A privileged user within the guest VM could have caused a
heap overflow in the device model process, potentially escalating their
privileges to that of the device model process (bsc#1028655)
These non-security issues were fixed:
– bsc#1029827: Additional xenstore patch
– bsc#1036146: Xen VM dumped core to wrong path
– bsc#1022703: Prevent Xen HVM guest with OVMF to hang with unattached
CDRom
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
– SUSE Linux Enterprise Software Development Kit 12-SP2:
zypper in -t patch SUSE-SLE-SDK-12-SP2-2017-663=1
– SUSE Linux Enterprise Server 12-SP2:
zypper in -t patch SUSE-SLE-SERVER-12-SP2-2017-663=1
– SUSE Linux Enterprise Desktop 12-SP2:
zypper in -t patch SUSE-SLE-DESKTOP-12-SP2-2017-663=1
To bring your system up-to-date, use “zypper patch”.
Package List:
– SUSE Linux Enterprise Software Development Kit 12-SP2 (aarch64 x86_64):
xen-debugsource-4.7.2_04-39.1
xen-devel-4.7.2_04-39.1
– SUSE Linux Enterprise Server 12-SP2 (x86_64):
xen-4.7.2_04-39.1
xen-debugsource-4.7.2_04-39.1
xen-doc-html-4.7.2_04-39.1
xen-libs-32bit-4.7.2_04-39.1
xen-libs-4.7.2_04-39.1
xen-libs-debuginfo-32bit-4.7.2_04-39.1
xen-libs-debuginfo-4.7.2_04-39.1
xen-tools-4.7.2_04-39.1
xen-tools-debuginfo-4.7.2_04-39.1
xen-tools-domU-4.7.2_04-39.1
xen-tools-domU-debuginfo-4.7.2_04-39.1
– SUSE Linux Enterprise Desktop 12-SP2 (x86_64):
xen-4.7.2_04-39.1
xen-debugsource-4.7.2_04-39.1
xen-libs-32bit-4.7.2_04-39.1
xen-libs-4.7.2_04-39.1
xen-libs-debuginfo-32bit-4.7.2_04-39.1
xen-libs-debuginfo-4.7.2_04-39.1
References:
https://www.suse.com/security/cve/CVE-2016-9603.html
https://www.suse.com/security/cve/CVE-2017-7718.html
https://bugzilla.suse.com/1022703
https://bugzilla.suse.com/1028655
https://bugzilla.suse.com/1029827
https://bugzilla.suse.com/1030144
https://bugzilla.suse.com/1034843
https://bugzilla.suse.com/1034844
https://bugzilla.suse.com/1034994
https://bugzilla.suse.com/1036146
–
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
SUSE Security Update: Security update for xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2017:1146-1
Rating: important
References: #1028655 #1033948 #1034843 #1034844 #1034845
#1034994 #1035483
Cross-References: CVE-2016-9603 CVE-2017-7718 CVE-2017-7980
CVE-2017-7995
Affected Products:
SUSE OpenStack Cloud 5
SUSE Manager Proxy 2.1
SUSE Manager 2.1
SUSE Linux Enterprise Server 11-SP3-LTSS
SUSE Linux Enterprise Point of Sale 11-SP3
______________________________________________________________________________
An update that solves four vulnerabilities and has three
fixes is now available.
Description:
This update for xen fixes several security issues:
- A malicious 64-bit PV guest may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks by placing a IRET hypercall in the middle of a multicall batch
(XSA-213, bsc#1034843)
- A malicious pair of guests may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks because of a missing check when transfering pages via
GNTTABOP_transfer (XSA-214, bsc#1034844).
- CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS
privileged users to cause a denial of service (out-of-bounds read and
QEMU process crash) via vectors related to copying VGA data via the
cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions
(bsc#1034994).
- CVE-2016-9603: A privileged user within the guest VM could have caused a
heap overflow in the device model process, potentially escalating their
privileges to that of the device model process (bsc#1028655)
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE OpenStack Cloud 5:
zypper in -t patch sleclo50sp3-xen-13085=1
- SUSE Manager Proxy 2.1:
zypper in -t patch slemap21-xen-13085=1
- SUSE Manager 2.1:
zypper in -t patch sleman21-xen-13085=1
- SUSE Linux Enterprise Server 11-SP3-LTSS:
zypper in -t patch slessp3-xen-13085=1
- SUSE Linux Enterprise Point of Sale 11-SP3:
zypper in -t patch sleposp3-xen-13085=1
To bring your system up-to-date, use “zypper patch”.
Package List:
- SUSE OpenStack Cloud 5 (x86_64):
xen-4.2.5_21-41.1
xen-doc-html-4.2.5_21-41.1
xen-doc-pdf-4.2.5_21-41.1
xen-kmp-default-4.2.5_21_3.0.101_0.47.99-41.1
xen-libs-32bit-4.2.5_21-41.1
xen-libs-4.2.5_21-41.1
xen-tools-4.2.5_21-41.1
xen-tools-domU-4.2.5_21-41.1
- SUSE Manager Proxy 2.1 (x86_64):
xen-4.2.5_21-41.1
xen-doc-html-4.2.5_21-41.1
xen-doc-pdf-4.2.5_21-41.1
xen-kmp-default-4.2.5_21_3.0.101_0.47.99-41.1
xen-libs-32bit-4.2.5_21-41.1
xen-libs-4.2.5_21-41.1
xen-tools-4.2.5_21-41.1
xen-tools-domU-4.2.5_21-41.1
- SUSE Manager 2.1 (x86_64):
xen-4.2.5_21-41.1
xen-doc-html-4.2.5_21-41.1
xen-doc-pdf-4.2.5_21-41.1
xen-kmp-default-4.2.5_21_3.0.101_0.47.99-41.1
xen-libs-32bit-4.2.5_21-41.1
xen-libs-4.2.5_21-41.1
xen-tools-4.2.5_21-41.1
xen-tools-domU-4.2.5_21-41.1
- SUSE Linux Enterprise Server 11-SP3-LTSS (i586 x86_64):
xen-kmp-default-4.2.5_21_3.0.101_0.47.99-41.1
xen-libs-4.2.5_21-41.1
xen-tools-domU-4.2.5_21-41.1
- SUSE Linux Enterprise Server 11-SP3-LTSS (x86_64):
xen-4.2.5_21-41.1
xen-doc-html-4.2.5_21-41.1
xen-doc-pdf-4.2.5_21-41.1
xen-libs-32bit-4.2.5_21-41.1
xen-tools-4.2.5_21-41.1
- SUSE Linux Enterprise Server 11-SP3-LTSS (i586):
xen-kmp-pae-4.2.5_21_3.0.101_0.47.99-41.1
- SUSE Linux Enterprise Point of Sale 11-SP3 (i586):
xen-kmp-default-4.2.5_21_3.0.101_0.47.99-41.1
xen-kmp-pae-4.2.5_21_3.0.101_0.47.99-41.1
xen-libs-4.2.5_21-41.1
xen-tools-domU-4.2.5_21-41.1
References:
https://www.suse.com/security/cve/CVE-2016-9603.html
https://www.suse.com/security/cve/CVE-2017-7718.html
https://www.suse.com/security/cve/CVE-2017-7980.html
https://www.suse.com/security/cve/CVE-2017-7995.html
https://bugzilla.suse.com/1028655
https://bugzilla.suse.com/1033948
https://bugzilla.suse.com/1034843
https://bugzilla.suse.com/1034844
https://bugzilla.suse.com/1034845
https://bugzilla.suse.com/1034994
https://bugzilla.suse.com/1035483
–
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
SUSE Security Update: Security update for xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2017:1148-1
Rating: important
References: #1029827 #1034843 #1034844 #1034845 #1034994
#1035483
Cross-References: CVE-2017-7718 CVE-2017-7980
Affected Products:
SUSE Linux Enterprise Server for SAP 12
SUSE Linux Enterprise Server 12-LTSS
______________________________________________________________________________
An update that solves two vulnerabilities and has four
fixes is now available.
Description:
This update for xen fixes several issues.
These security issues were fixed:
- CVE-2017-7980: An out-of-bounds r/w access issues in the Cirrus CLGD
54xx VGA Emulator support allowed privileged user inside guest to use
this flaw to crash the Qemu process resulting in DoS or potentially
execute arbitrary code on a host with privileges of Qemu process on the
host (bsc#1035483).
- A malicious 64-bit PV guest may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks by placing a IRET hypercall in the middle of a multicall batch
(XSA-213, bsc#1034843)
- A malicious pair of guests may be able to access all of system memory,
allowing for all of privilege escalation, host crashes, and information
leaks because of a missing check when transfering pages via
GNTTABOP_transfer (XSA-214, bsc#1034844).
- Incorrect checks when handling exceptions allowed a malicious or buggy
64-bit PV guest to modify part of a physical memory page not belonging
to it, potentially allowing for all of privilege escalation, host or
other guest crashes, and information leaks (XSA-215, bsc#1034845)
- CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS
privileged users to cause a denial of service (out-of-bounds read and
QEMU process crash) via vectors related to copying VGA data via the
cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions
(bsc#1034994).
This non-security issue was fixed:
- bsc#1029827: Additional xenstore fixes
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Server for SAP 12:
zypper in -t patch SUSE-SLE-SAP-12-2017-665=1
- SUSE Linux Enterprise Server 12-LTSS:
zypper in -t patch SUSE-SLE-SERVER-12-2017-665=1
To bring your system up-to-date, use “zypper patch”.
Package List:
- SUSE Linux Enterprise Server for SAP 12 (x86_64):
xen-4.4.4_18-22.39.1
xen-debugsource-4.4.4_18-22.39.1
xen-doc-html-4.4.4_18-22.39.1
xen-kmp-default-4.4.4_18_k3.12.61_52.69-22.39.1
xen-kmp-default-debuginfo-4.4.4_18_k3.12.61_52.69-22.39.1
xen-libs-32bit-4.4.4_18-22.39.1
xen-libs-4.4.4_18-22.39.1
xen-libs-debuginfo-32bit-4.4.4_18-22.39.1
xen-libs-debuginfo-4.4.4_18-22.39.1
xen-tools-4.4.4_18-22.39.1
xen-tools-debuginfo-4.4.4_18-22.39.1
xen-tools-domU-4.4.4_18-22.39.1
xen-tools-domU-debuginfo-4.4.4_18-22.39.1
- SUSE Linux Enterprise Server 12-LTSS (x86_64):
xen-4.4.4_18-22.39.1
xen-debugsource-4.4.4_18-22.39.1
xen-doc-html-4.4.4_18-22.39.1
xen-kmp-default-4.4.4_18_k3.12.61_52.69-22.39.1
xen-kmp-default-debuginfo-4.4.4_18_k3.12.61_52.69-22.39.1
xen-libs-32bit-4.4.4_18-22.39.1
xen-libs-4.4.4_18-22.39.1
xen-libs-debuginfo-32bit-4.4.4_18-22.39.1
xen-libs-debuginfo-4.4.4_18-22.39.1
xen-tools-4.4.4_18-22.39.1
xen-tools-debuginfo-4.4.4_18-22.39.1
xen-tools-domU-4.4.4_18-22.39.1
xen-tools-domU-debuginfo-4.4.4_18-22.39.1
References:
https://www.suse.com/security/cve/CVE-2017-7718.html
https://www.suse.com/security/cve/CVE-2017-7980.html
https://bugzilla.suse.com/1029827
https://bugzilla.suse.com/1034843
https://bugzilla.suse.com/1034844
https://bugzilla.suse.com/1034845
https://bugzilla.suse.com/1034994
https://bugzilla.suse.com/1035483
–
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
$downloadlink = get_field('download_link'); ?>