FlawAtlas
Search the atlas
SUSE-SU-2015:0701-1 Not scored

Security update for xen

Xen was updated 4.4.2_01 to address three security issues and functional bugs. The following vulnerabilities were fixed: - Long latency MMIO mapping operations are not preemptible (XSA-125, CVE-2015-2752, bnc#922705) - Unmediated PCI command register access in qemu (XSA-126, CVE-2015-2756, bnc#922706) - Certain domctl operations may be abused to lock up the host (XSA-127, CVE-2015-2751, bnc#922709) The following non-security bugs were fixed: - xen dmesg contains bogus output in early boot (bnc#923758) - Xentop doesn't display disk statistics for VMs using qdisks (bnc#921842) The following functionality was enabled: - Enable spice support in qemu for x86_64 - Add Qxl vga support

Exploit probability Not scored
Published April 1, 2015
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 xen
SUSE:Linux Enterprise Server 12 xen
SUSE:Linux Enterprise Server for SAP Applications 12 xen
SUSE:Linux Enterprise Software Development Kit 12 xen

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2015:0701-1

Xen was updated 4.4.2_01 to address three security issues and functional bugs. The following vulnerabilities were fixed: - Long latency MMIO mapping operations are not preemptible (XSA-125, CVE-2015-2752, bnc#922705) - Unmediated PCI command register access in qemu (XSA-126, CVE-2015-2756, bnc#922706) - Certain domctl operations may be abused to lock up the host (XSA-127, CVE-2015-2751, bnc#922709) The following non-security bugs were fixed: - xen dmesg contains bogus output in early boot (bnc#923758) - Xentop doesn't display disk statistics for VMs using qdisks (bnc#921842) The following functionality was enabled: - Enable spice support in qemu for x86_64 - Add Qxl vga support

View original source

05 / REFERENCES

Further evidence