SUSE-SU-2015:0701-1
Vulnerability Summary
Timeline
Description
Security update for xen Xen was updated 4.4.2_01 to address three security issues and functional bugs. The following vulnerabilities were fixed: - Long latency MMIO mapping operations are not preemptible (XSA-125, CVE-2015-2752, bnc#922705) - Unmediated PCI command register access in qemu (XSA-126, CVE-2015-2756, bnc#922706) - Certain domctl operations may be abused to lock up the host (XSA-127, CVE-2015-2751, bnc#922709) The following non-security bugs were fixed: - xen dmesg contains bogus output in early boot (bnc#923758) - Xentop doesn't display disk statistics for VMs using qdisks (bnc#921842) The following functionality was enabled: - Enable spice support in qemu for x86_64 - Add Qxl vga support
Affected Systems
- suse•xen&distro=SUSE Linux Enterprise Desktop 12
< 4.4.2_02-15.1
- suse•xen&distro=SUSE Linux Enterprise Server 12
< 4.4.2_02-15.1
- suse•xen&distro=SUSE Linux Enterprise Server for SAP Applications 12
< 4.4.2_02-15.1
- suse•xen&distro=SUSE Linux Enterprise Software Development Kit 12
< 4.4.2_02-15.1
References (9)
- https://www.suse.com/support/update/announcement/2015/suse-su-20150701-1/
- https://bugzilla.suse.com/921842
- https://bugzilla.suse.com/922705
- https://bugzilla.suse.com/922706
- https://bugzilla.suse.com/922709
- https://bugzilla.suse.com/923758
- https://www.suse.com/security/cve/CVE-2015-2751
- https://www.suse.com/security/cve/CVE-2015-2752
- https://www.suse.com/security/cve/CVE-2015-2756