rpm package
suse/xen&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4
Vulnerabilities (148)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-19965 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (a | ||
| CVE-2018-19964 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 8, 2018 | An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions. | ||
| CVE-2018-19963 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 8, 2018 | An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled. | ||
| CVE-2018-19962 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | ||
| CVE-2018-19961 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 8, 2018 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | ||
| CVE-2018-19665 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Dec 6, 2018 | The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption. | ||
| CVE-2018-18883 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Nov 1, 2018 | An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted. | ||
| CVE-2018-17963 | — | < 4.11.1_02-2.3.1 | 4.11.1_02-2.3.1 | Oct 9, 2018 | qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact. |
- CVE-2018-19965Dec 8, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (a
- CVE-2018-19964Dec 8, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.
- CVE-2018-19963Dec 8, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.
- CVE-2018-19962Dec 8, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
- CVE-2018-19961Dec 8, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
- CVE-2018-19665Dec 6, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
- CVE-2018-18883Nov 1, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.
- CVE-2018-17963Oct 9, 2018affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
Page 8 of 8