FlawAtlas
Search the atlas
SUSE-SU-2024:2535-1 Not scored

Security update for xen

This update for xen fixes the following issues: - CVE-2023-28746: Register File Data Sampling (XSA-452, bsc#1221332) - CVE-2023-46842: HVM hypercalls may trigger Xen bug check (XSA-454, bsc#1221984) - CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (XSA-453, bsc#1221334) - CVE-2024-2201: Mitigation for Native Branch History Injection (XSA-456, bsc#1222453) - CVE-2024-31142: Fixed incorrect logic for BTC/SRSO mitigations (XSA-455, bsc#1222302) - CVE-2024-31143: Fixed double unlock in x86 guest IRQ handling (XSA-458, bsc#1227355)

Exploit probability Not scored
Published July 16, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS xen
SUSE:Linux Enterprise Server 15 SP2-LTSS xen
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 xen

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:2535-1

This update for xen fixes the following issues: - CVE-2023-28746: Register File Data Sampling (XSA-452, bsc#1221332) - CVE-2023-46842: HVM hypercalls may trigger Xen bug check (XSA-454, bsc#1221984) - CVE-2024-2193: Fixed GhostRace, a speculative race conditions. (XSA-453, bsc#1221334) - CVE-2024-2201: Mitigation for Native Branch History Injection (XSA-456, bsc#1222453) - CVE-2024-31142: Fixed incorrect logic for BTC/SRSO mitigations (XSA-455, bsc#1222302) - CVE-2024-31143: Fixed double unlock in x86 guest IRQ handling (XSA-458, bsc#1227355)

View original source

05 / REFERENCES

Further evidence