SuSE: 2014:0372-1: important: Xen
Summary
The SUSE Linux Enterprise Server 11 Service Pack 2 LTSS Xen hypervisor and toolset has been updated to fix various security issues and several bugs. The following security issues have been addressed: * XSA-88: CVE-2014-1950: Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors. (bnc#861256) * XSA-87: CVE-2014-1666: The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service (host or guest malfunction) or possibly gain privileges...
Read the Full AdvisoryReferences
#831120 #833483 #842417 #846849 #848014 #849667
#849668 #853049 #860163 #860302 #861256
Cross- CVE-2013-2212 CVE-2013-4553 CVE-2013-4554
CVE-2013-6885 CVE-2014-1666 CVE-2014-1891
CVE-2014-1892 CVE-2014-1893 CVE-2014-1894
CVE-2014-1950
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
https://www.suse.com/security/cve/CVE-2013-2212.html
https://www.suse.com/security/cve/CVE-2013-4553.html
https://www.suse.com/security/cve/CVE-2013-4554.html
https://www.suse.com/security/cve/CVE-2013-6885.html
https://www.suse.com/security/cve/CVE-2014-1666.html
https://www.suse.com/security/cve/CVE-2014-1891.html
https://www.suse.com/security/cve/CVE-2014-1892.html
https://www.suse.com/security/cve/CVE-2014-1893.html
https://www.suse.com/security/cve/CVE-2014-1894.html
https://www.suse.com/security/cve/CVE-2014-1950.html
https://bugzilla.novell.com/831120
https:/...
Read the Full Advisory