rpm package
suse/xen&distro=SUSE Linux Enterprise Server 11 SP4-LTSS
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
Vulnerabilities (79)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-25596 | Med | 5.5 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it t | |
| CVE-2020-25595 | Hig | 7.8 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Sep 23, 2020 | An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specific | |
| CVE-2020-14364 | Med | 5.0 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Aug 31, 2020 | An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw all | |
| CVE-2020-15567 | Hig | 7.8 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-at | |
| CVE-2020-15565 | Hig | 8.8 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Jul 7, 2020 | An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require fl | |
| CVE-2020-0543 | Med | 5.5 | < 4.4.4_44-61.55.1 | 4.4.4_44-61.55.1 | Jun 15, 2020 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| CVE-2020-11742 | Med | 5.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Apr 14, 2020 | An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to return 0 for success, and a negative number for errors. The fix for CVE-2017-12135 int | |
| CVE-2020-11741 | Hig | 8.8 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Apr 14, 2020 | An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the admini | |
| CVE-2020-11740 | Med | 5.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Apr 14, 2020 | An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. Thes | |
| CVE-2020-8608 | Med | 5.6 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Feb 6, 2020 | In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code. | |
| CVE-2020-7211 | Hig | 7.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Jan 21, 2020 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | |
| CVE-2019-19583 | Hig | 7.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the nee | |
| CVE-2019-19580 | Med | 6.6 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in rest | |
| CVE-2019-19578 | Hig | 8.8 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at i | |
| CVE-2019-19577 | Hig | 7.2 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically | |
| CVE-2019-19579 | Med | 6.8 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Dec 4, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the us | |
| CVE-2018-12207 | Med | 6.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Nov 14, 2019 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| CVE-2019-11135 | Med | 6.5 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Nov 14, 2019 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| CVE-2019-18425 | Cri | 9.8 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table acce | |
| CVE-2019-18424 | Med | 6.8 | < 4.4.4_42-61.52.1 | 4.4.4_42-61.52.1 | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI devi |
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it t
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specific
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw all
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-at
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require fl
- affected < 4.4.4_44-61.55.1fixed 4.4.4_44-61.55.1
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of bad continuation handling in GNTTABOP_copy. Grant table operations are expected to return 0 for success, and a negative number for errors. The fix for CVE-2017-12135 int
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the admini
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. Thes
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the nee
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in rest
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at i
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height updates. When running on AMD systems with an IOMMU, Xen attempted to dynamically
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the us
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table acce
- affected < 4.4.4_42-61.52.1fixed 4.4.4_42-61.52.1
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI devi
Page 3 of 4