Security update for xen
This update for xen fixes the following issues: - CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744). - CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746). - CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443) (bsc#1215747). - CVE-2023-34327, CVE-2023-34328: Fixed multiple issues with AMD x86 debugging functionality for guests (XSA-444) (bsc#1215748).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for xen fixes the following issues: - CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744). - CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746). - CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443) (bsc#1215747). - CVE-2023-34327, CVE-2023-34328: Fixed multiple issues with AMD x86 debugging functionality for guests (XSA-444) (bsc#1215748).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1215744
- https://bugzilla.suse.com/1215746
- https://bugzilla.suse.com/1215747
- https://bugzilla.suse.com/1215748
- https://www.suse.com/security/cve/CVE-2023-34323
- https://www.suse.com/security/cve/CVE-2023-34325
- https://www.suse.com/security/cve/CVE-2023-34326
- https://www.suse.com/security/cve/CVE-2023-34327
- https://www.suse.com/security/cve/CVE-2023-34328
- https://www.suse.com/support/update/announcement/2023/suse-su-20234184-1/