Alerts This Week
Warning Icon 1 1,071
Alerts This Week
Warning Icon 1 1,071

SUSE: 2022:3925-1 Critical: Fix for Xen Denial of Service Vulnerability

suse
Calendar Grey November 9, 2022
Dist Suse Esm H88
SUSE enhances safety for xen, addressing 20 major weaknesses. Urgent update directives provided.
An update that fixes 20 vulnerabilities is now available

Summary

This update for xen fixes the following issues: - CVE-2022-33746: Fixed DoS due to excessively long P2M pool freeing (bsc#1203806). - CVE-2022-33748: Fixed DoS due to race in locking (bsc#1203807). - CVE-2021-28689: Fixed speculative vulnerabilities with bare (non-shim) 32-bit PV guests (bsc#1185104). - CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318: xen: Xenstore: Guests can let xenstored run out of memory (bsc#1204482) - CVE-2022-42309: xen: Xenstore: Guests can crash xenstored (bsc#1204485) - CVE-2022-42310: xen: Xenstore: Guests can create orphaned Xenstore nodes (bsc#1204487) - CVE-2022-42319: xen: Xenstore: Guests can cause Xenstore to not free temporary memory (bsc#1204488)

References

#1185104 #1193923 #1203806 #1203807 #1204482

#1204485 #1204487 #1204488 #1204489 #1204490

#1204494 #1204496

Cross- CVE-2021-28689 CVE-2022-33746 CVE-2022-33748

CVE-2022-42309 CVE-2022-42310 CVE-2022-42311

CVE-2022-42312 CVE-2022-42313 CVE-2022-42314

CVE-2022-42315 CVE-2022-42316 CVE-2022-42317

CVE-2022-42318 CVE-2022-42319 CVE-2022-42320

CVE-2022-42321 CVE-2022-42322 CVE-2022-42323

CVE-2022-42325 CVE-2022-42326

CVSS scores:

CVE-2021-28689 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2021-28689 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2022-33746 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CVE-2022-33746 (SUSE): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3925-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here