VYPR

rpm package

suse/xen&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP4

pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Vulnerabilities (148)

  • CVE-2018-19965Dec 8, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (a

  • CVE-2018-19964Dec 8, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.

  • CVE-2018-19963Dec 8, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.

  • CVE-2018-19962Dec 8, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

  • CVE-2018-19961Dec 8, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

  • CVE-2018-19665Dec 6, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.

  • CVE-2018-18883Nov 1, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.

  • CVE-2018-17963Oct 9, 2018
    affected < 4.11.1_02-2.3.1fixed 4.11.1_02-2.3.1

    qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.

Page 8 of 8