Security update for xen

This update for xen fixes several issues.

These security issues were fixed:

- A malicious 64-bit PV guest may be able to access all of system memory, allowing for all of privilege escalation, host crashes, and information leaks by placing a IRET hypercall in the middle of a multicall batch (XSA-213, bsc#1034843)
- A malicious pair of guests may be able to access all of system memory, allowing for all of privilege escalation, host crashes, and information leaks because of a missing check when transfering pages via GNTTABOP_transfer (XSA-214, bsc#1034844).
- CVE-2017-7718: hw/display/cirrus_vga_rop.h allowed local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions (bsc#1034994).
- CVE-2016-9603: A privileged user within the guest VM could have caused a heap overflow in the device model process, potentially escalating their privileges to that of the device model process (bsc#1028655)

These non-security issues were fixed:

- bsc#1029827: Additional xenstore patch
- bsc#1036146: Xen VM dumped core to wrong path
- bsc#1022703: Prevent Xen HVM guest with OVMF to hang with unattached CDRom

This update was imported from the SUSE:SLE-12-SP2:Update update project.

Fixed bugs
bnc#1028655
VUL-0: CVE-2016-9603: xen: Cirrus VGA Heap overflow via display refresh (XSA-211)
bnc#1029827
Forward port xenstored
bnc#1034994
VUL-0: CVE-2017-7718: xen: qemu: display: cirrus: OOB read access issue
bnc#1036146
L3: sles12sp2 xen VM dumps core to wrong path
bnc#1022703
Xen HVM guest with OVMF hangs with unattached CDRom
bnc#1030144
VUL-0: xen: xenstore denial of service via repeated update (XSA-206)
bnc#1034844
VUL-0: xen: grant transfer allows PV guest to elevate privileges (XSA-214)
bnc#1034843
VUL-0: xen: x86: 64bit PV guest breakout via pagetable use-after-mode-change (XSA-213)
Selected Binaries
openSUSE Build Service is sponsored by