FlawAtlas
Search the atlas
SUSE-SU-2020:0334-1 Not scored

Security update for xen

This update for xen fixes the following issues: - CVE-2020-7211: potential directory traversal using relative paths via tftp server on Windows host (bsc#1161181). - CVE-2019-19579: Device quarantine for alternate pci assignment methods (bsc#1157888). - CVE-2019-19581: find_next_bit() issues (bsc#1158003). - CVE-2019-19583: VMentry failure with debug exceptions and blocked states (bsc#1158004). - CVE-2019-19578: Linear pagetable use / entry miscounts (bsc#1158005). - CVE-2019-19580: Further issues with restartable PV type change operations (bsc#1158006). - CVE-2019-19577: dynamic height for the IOMMU pagetables (bsc#1158007). - CVE-2019-18420: VCPUOP_initialise DoS (bsc#1154448). - CVE-2019-18425: missing descriptor table limit checking in x86 PV emulation (bsc#1154456). - CVE-2019-18421: Issues with restartable PV type change operations (bsc#1154458). - CVE-2019-18424: passed through PCI devices may corrupt host memory after deassignment (bsc#1154461). - CVE-2018-12207: Machine Check Error Avoidance on Page Size Change (aka IFU issue) (bsc#1155945). - CVE-2019-11135: TSX Asynchronous Abort (TAA) issue (bsc#1152497).

Exploit probability Not scored
Published February 6, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP2-BCL xen
SUSE:Linux Enterprise Server 12 SP2-LTSS xen
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 xen
SUSE:OpenStack Cloud 7 xen

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:0334-1

This update for xen fixes the following issues: - CVE-2020-7211: potential directory traversal using relative paths via tftp server on Windows host (bsc#1161181). - CVE-2019-19579: Device quarantine for alternate pci assignment methods (bsc#1157888). - CVE-2019-19581: find_next_bit() issues (bsc#1158003). - CVE-2019-19583: VMentry failure with debug exceptions and blocked states (bsc#1158004). - CVE-2019-19578: Linear pagetable use / entry miscounts (bsc#1158005). - CVE-2019-19580: Further issues with restartable PV type change operations (bsc#1158006). - CVE-2019-19577: dynamic height for the IOMMU pagetables (bsc#1158007). - CVE-2019-18420: VCPUOP_initialise DoS (bsc#1154448). - CVE-2019-18425: missing descriptor table limit checking in x86 PV emulation (bsc#1154456). - CVE-2019-18421: Issues with restartable PV type change operations (bsc#1154458). - CVE-2019-18424: passed through PCI devices may corrupt host memory after deassignment (bsc#1154461). - CVE-2018-12207: Machine Check Error Avoidance on Page Size Change (aka IFU issue) (bsc#1155945). - CVE-2019-11135: TSX Asynchronous Abort (TAA) issue (bsc#1152497).

View original source

05 / REFERENCES

Further evidence