FlawAtlas
Search the atlas
SUSE-SU-2025:02326-1 Not scored

Security update for xen

This update for xen fixes the following issues: Security fixes: - CVE-2024-28956: Fixed Intel CPU: Indirect Target Selection (ITS) (XSA-469) (bsc#1243117) - CVE-2024-53241: Fixed Xen hypercall page unsafe against speculative attacks (XSA-466) (bsc#1234282) - CVE-2025-1713: Fixed deadlock potential with VT-d and legacy PCI device pass-through (XSA-467) (bsc#1238043) - CVE-2024-36350, CVE-2024-36357: More AMD transient execution attacks (bsc#1246112, XSA-471) - CVE-2025-27465: Incorrect stubs exception handling for flags recovery (bsc#1244644, XSA-470) Other fixes: - Upstream bug fixes (bsc#1027519)

Exploit probability Not scored
Published July 16, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS xen
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS xen
SUSE:Linux Enterprise Micro 5.3 xen
SUSE:Linux Enterprise Micro 5.4 xen
SUSE:Linux Enterprise Server 15 SP4-LTSS xen
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 xen
SUSE:Manager Proxy 4.3 xen
SUSE:Manager Server 4.3 xen

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:02326-1

This update for xen fixes the following issues: Security fixes: - CVE-2024-28956: Fixed Intel CPU: Indirect Target Selection (ITS) (XSA-469) (bsc#1243117) - CVE-2024-53241: Fixed Xen hypercall page unsafe against speculative attacks (XSA-466) (bsc#1234282) - CVE-2025-1713: Fixed deadlock potential with VT-d and legacy PCI device pass-through (XSA-467) (bsc#1238043) - CVE-2024-36350, CVE-2024-36357: More AMD transient execution attacks (bsc#1246112, XSA-471) - CVE-2025-27465: Incorrect stubs exception handling for flags recovery (bsc#1244644, XSA-470) Other fixes: - Upstream bug fixes (bsc#1027519)

View original source

05 / REFERENCES

Further evidence