SUSE-SU-2019:2753-1

Advisory lineage Upstream: 16 Downstream: 0
Published: 23 Oct 2019, 11:45
Last modified:04 Feb 2026, 03:34

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Oct 2019, 11:45
Published
Vulnerability first disclosed
04 Feb 2026, 03:34
Last Modified
Vulnerability information updated

Description

Security update for xen This update for xen to version 4.11.2 fixes the following issues: Security issues fixed: - CVE-2019-15890: Fixed a use-after-free in SLiRP networking implementation of QEMU emulator which could have led to Denial of Service (bsc#1149813). - CVE-2019-12068: Fixed an issue in lsi which could lead to an infinite loop and denial of service (bsc#1146874). - CVE-2019-14378: Fixed a heap buffer overflow in SLiRp networking implementation of QEMU emulator which could have led to execution of arbitrary code with privileges of the QEMU process (bsc#1143797). Other issues fixed: - Fixed an HPS bug which did not allow to install Windows Server 2016 with 2 CPUs setting or above (bsc#1137717). - Fixed a segmentation fault in Libvrtd during live migration to a VM (bsc#1145774). - Fixed an issue where libxenlight could not create new domain (bsc#1131811). - Fixed an issue where attached pci devices were lost after reboot (bsc#1129642). - Fixed an issue where Xen could not pre-allocate 1 shadow page (bsc#1145240).

Affected Systems

  • susexen&distro=SUSE Linux Enterprise Desktop 12 SP4

    < 4.11.2_02-2.14.2

  • susexen&distro=SUSE Linux Enterprise Server 12 SP4

    < 4.11.2_02-2.14.2

  • susexen&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4

    < 4.11.2_02-2.14.2

  • susexen&distro=SUSE Linux Enterprise Software Development Kit 12 SP4

    < 4.11.2_02-2.14.2

References (37)