SuSE: 2012:1615-1: important: Xen
Summary
This update fixes the following security issues in xen: * CVE-2012-5510: Grant table version switch list corruption vulnerability (XSA-26) * CVE-2012-5511: Several HVM operations do not validate the range of their inputs (XSA-27) * CVE-2012-5512: HVMOP_get_mem_access crash / HVMOP_set_mem_access information leak (XSA-28) * CVE-2012-5513: XENMEM_exchange may overwrite hypervisor memory (XSA-29) * CVE-2012-5514: Missing unlock in guest_physmap_mark_populate_on_demand() (XSA-30) * CVE-2012-5515: Several memory hypercall operations allow invalid extent order values (XSA-31) Also the following bugs have been fixed and upstream patches have been applied: * FATAL PAGE FAULT in hypervisor (arch_do_domctl) * 25931-x86-domctl-iomem-mapping-checks.patch * 26132-tmem-save-NULL-check.patch * 26134-x86-shadow-invlpg-check.patch * 26148-vcpu-timer-overflow.patch (Replaces CVE-2012-4535-xsa20.patch) * 26149-x86-p2m-physmap-err...
Read the Full AdvisoryReferences
#777628 #789940 #789944 #789945 #789948 #789950
#789951 #789988 #792476
Cross- CVE-2012-5510 CVE-2012-5511 CVE-2012-5512
CVE-2012-5513 CVE-2012-5514 CVE-2012-5515
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2012-5510.html
https://www.suse.com/security/cve/CVE-2012-5511.html
https://www.suse.com/security/cve/CVE-2012-5512.html
https://www.suse.com/security/cve/CVE-2012-5513.html
https://www.suse.com/security/cve/CVE-2012-5514.html
https://www.suse.com/security/cve/CVE-2012-5515.html
https://bugzilla.novell.com/777628
https://bugzilla.novell.com/789940
https://bugzilla.novell.com/789944
https://bugzilla.novell.com/789945
https://bugzilla....
Read the Full Advisory