SuSE: 2011:1057-1: important: Xen
Summary
SUSE Security Update: Security update for Xen
______________________________________________________________________________
Announcement ID: SUSE-SU-2011:1057-1
Rating: important
References: #654798 #659070 #679344 #684297 #704380 #712038
Cross-References: CVE-2011-1166 CVE-2011-1936 CVE-2011-2901
Affected Products:
SUSE Linux Enterprise Server 10 SP3
SLE SDK 10 SP3
______________________________________________________________________________
An update that solves three vulnerabilities and has three
fixes is now available.
Description:
This update fixes various bugs in XEN:
The following security issues have been fixed:
* A denial of service (Host Crash) in the XEN
hypervisor. (CVE-2011-2901)
* A bug was found in the way Xen handles CPUID
instruction emulation during VM exits. An unprivileged
guest user can potentially use this flaw to crash the
guest. (CVE-2011-1936)
* A 64-bit guest can get one of its vcpus into
non-kernel mode without first providing a valid non-kernel
pagetable. The observed failure mode was usually a hard
lockup of the host (host denial of service). (CVE-2011-1166)
It fixes also the following bugs:
* bnc#654798 - SLES 10 SP3 XEN: Device /dev/xvdp is
already connected error when starting multiple vm's
* bnc#684297 - HVM taking too long to dump vmcore
Security Issue references:
* CVE-2011-2901
References