Security update for xen
This update for xen fixes the following issues: - CVE-2023-20588: AMD CPU transitional execution leak via division by zero (XSA-439) (bsc#1215474). - CVE-2023-34322: top-level shadow reference dropped too early for 64-bit PV guests (XSA-438) (bsc#1215145). - CVE-2023-34325: Multiple vulnerabilities in libfsimage disk handling (XSA-443) (bsc#1215747). - CVE-2023-34326: x86/AMD: missing IOMMU TLB flushing (XSA-442) (bsc#1215746). - CVE-2023-34327,CVE-2023-34328: x86/AMD: Debug Mask handling (XSA-444) (bsc#1215748). - CVE-2023-46835: x86/AMD: mismatch in IOMMU quarantine page table levels (XSA-445) (bsc#1216654). - CVE-2023-46836: x86: BTC/SRSO fixes not fully effective (XSA-446) (bsc#1216807). - Upstream bug fixes (bsc#1027519)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for xen fixes the following issues: - CVE-2023-20588: AMD CPU transitional execution leak via division by zero (XSA-439) (bsc#1215474). - CVE-2023-34322: top-level shadow reference dropped too early for 64-bit PV guests (XSA-438) (bsc#1215145). - CVE-2023-34325: Multiple vulnerabilities in libfsimage disk handling (XSA-443) (bsc#1215747). - CVE-2023-34326: x86/AMD: missing IOMMU TLB flushing (XSA-442) (bsc#1215746). - CVE-2023-34327,CVE-2023-34328: x86/AMD: Debug Mask handling (XSA-444) (bsc#1215748). - CVE-2023-46835: x86/AMD: mismatch in IOMMU quarantine page table levels (XSA-445) (bsc#1216654). - CVE-2023-46836: x86: BTC/SRSO fixes not fully effective (XSA-446) (bsc#1216807). - Upstream bug fixes (bsc#1027519)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1027519
- https://bugzilla.suse.com/1215145
- https://bugzilla.suse.com/1215474
- https://bugzilla.suse.com/1215746
- https://bugzilla.suse.com/1215747
- https://bugzilla.suse.com/1215748
- https://bugzilla.suse.com/1216654
- https://bugzilla.suse.com/1216807
- https://www.suse.com/security/cve/CVE-2023-20588
- https://www.suse.com/security/cve/CVE-2023-34322
- https://www.suse.com/security/cve/CVE-2023-34325
- https://www.suse.com/security/cve/CVE-2023-34326
- https://www.suse.com/security/cve/CVE-2023-34327
- https://www.suse.com/security/cve/CVE-2023-34328
- https://www.suse.com/security/cve/CVE-2023-46835
- https://www.suse.com/security/cve/CVE-2023-46836
- https://www.suse.com/support/update/announcement/2023/suse-su-20234476-1/