{"affected":[{"ecosystem_specific":{"binaries":[{"xen-devel":"4.4.4_08-40.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"xen","purl":"pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.4.4_08-40.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xen":"4.4.4_08-40.2","xen-doc-html":"4.4.4_08-40.2","xen-kmp-default":"4.4.4_08_3.0.101_80-40.2","xen-kmp-pae":"4.4.4_08_3.0.101_80-40.2","xen-libs":"4.4.4_08-40.2","xen-libs-32bit":"4.4.4_08-40.2","xen-tools":"4.4.4_08-40.2","xen-tools-domU":"4.4.4_08-40.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"xen","purl":"pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.4.4_08-40.2"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"xen":"4.4.4_08-40.2","xen-doc-html":"4.4.4_08-40.2","xen-kmp-default":"4.4.4_08_3.0.101_80-40.2","xen-kmp-pae":"4.4.4_08_3.0.101_80-40.2","xen-libs":"4.4.4_08-40.2","xen-libs-32bit":"4.4.4_08-40.2","xen-tools":"4.4.4_08-40.2","xen-tools-domU":"4.4.4_08-40.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"xen","purl":"pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.4.4_08-40.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for xen fixes several issues.\n\nThese security issues were fixed:\n- CVE-2016-7092: The get_page_from_l3e function in arch/x86/mm.c in Xen allowed local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables (bsc#995785)\n- CVE-2016-7093: Xen allowed local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation (bsc#995789)\n- CVE-2016-7094: Buffer overflow in Xen allowed local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update (bsc#995792)\n- CVE-2016-7154: Use-after-free vulnerability in the FIFO event channel code in Xen allowed local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number (bsc#997731)\n- CVE-2016-6836: VMWARE VMXNET3 NIC device allowed privileged user inside the guest to leak information. It occured while processing transmit(tx) queue, when it reaches the end of packet (bsc#994761)\n- CVE-2016-6888: A integer overflow int the VMWARE VMXNET3 NIC device support, during the initialisation of new packets in the device, could have allowed a privileged user inside guest to crash the Qemu instance resulting in DoS (bsc#994772)\n- CVE-2016-6833: A use-after-free issue in the VMWARE VMXNET3 NIC device support allowed privileged user inside guest to crash the Qemu instance resulting in DoS (bsc#994775)\n- CVE-2016-6835: Buffer overflow in the VMWARE VMXNET3 NIC device support, causing an OOB read access (bsc#994625)\n- CVE-2016-6834: A infinite loop during packet fragmentation in the VMWARE VMXNET3 NIC device support allowed privileged user inside guest to crash the Qemu instance resulting in DoS (bsc#994421)\n- CVE-2016-6258: The PV pagetable code in arch/x86/mm.c in Xen allowed local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries (bsc#988675)\n\nThese non-security issues were fixed:\n- bsc#993507: virsh detach-disk failing to detach disk\n- bsc#991934: Xen hypervisor crash in csched_acct\n- bsc#992224: During boot of Xen Hypervisor, Failed to get contiguous memory for DMA\n- bsc#970135: New virtualization project clock test randomly fails on Xen \n- bsc#994136: Unplug also SCSI disks in qemu-xen-traditional for upstream unplug protocol\n- bsc#994136: xen_platform: unplug also SCSI disks in qemu-xen\n- bsc#971949: xl: Support (by ignoring) xl migrate --live. xl migrations are always live\n- bsc#990970: Add PMU support for Intel E7-8867 v4 (fam=6, model=79)\n- bsc#966467: Live Migration SLES 11 SP3 to SP4 on AMD\n","id":"SUSE-SU-2016:2507-1","modified":"2016-10-12T09:34:10Z","published":"2016-10-12T09:34:10Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2016/suse-su-20162507-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/966467"},{"type":"REPORT","url":"https://bugzilla.suse.com/970135"},{"type":"REPORT","url":"https://bugzilla.suse.com/971949"},{"type":"REPORT","url":"https://bugzilla.suse.com/988675"},{"type":"REPORT","url":"https://bugzilla.suse.com/990970"},{"type":"REPORT","url":"https://bugzilla.suse.com/991934"},{"type":"REPORT","url":"https://bugzilla.suse.com/992224"},{"type":"REPORT","url":"https://bugzilla.suse.com/993507"},{"type":"REPORT","url":"https://bugzilla.suse.com/994136"},{"type":"REPORT","url":"https://bugzilla.suse.com/994421"},{"type":"REPORT","url":"https://bugzilla.suse.com/994625"},{"type":"REPORT","url":"https://bugzilla.suse.com/994761"},{"type":"REPORT","url":"https://bugzilla.suse.com/994772"},{"type":"REPORT","url":"https://bugzilla.suse.com/994775"},{"type":"REPORT","url":"https://bugzilla.suse.com/995785"},{"type":"REPORT","url":"https://bugzilla.suse.com/995789"},{"type":"REPORT","url":"https://bugzilla.suse.com/995792"},{"type":"REPORT","url":"https://bugzilla.suse.com/997731"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6258"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6836"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-6888"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7154"}],"related":["CVE-2016-6258","CVE-2016-6833","CVE-2016-6834","CVE-2016-6835","CVE-2016-6836","CVE-2016-6888","CVE-2016-7092","CVE-2016-7093","CVE-2016-7094","CVE-2016-7154"],"summary":"Security update for xen","upstream":["CVE-2016-6258","CVE-2016-6833","CVE-2016-6834","CVE-2016-6835","CVE-2016-6836","CVE-2016-6888","CVE-2016-7092","CVE-2016-7093","CVE-2016-7094","CVE-2016-7154"]}