File _patchinfo of Package patchinfo.16559
<patchinfo incident="16559">
<issue tracker="bnc" id="1176344">VUL-0: CVE-2020-25595: xen: PCI passthrough code reading back hardware registers (XSA-337 v3)</issue>
<issue tracker="bnc" id="1173380">VUL-0: CVE-2020-15567: xen: XSA-328 - non-atomic modification of live EPT PTE</issue>
<issue tracker="bnc" id="1176348">VUL-0: CVE-2020-25600: xen: out of bounds event channels available to 32-bit x86 domains (XSA-342 v3)</issue>
<issue tracker="bnc" id="1172205">VUL-0: CVE-2020-0543: xen: XSA-320 v2 - Special Register Buffer Data Sampling (SRBDS) aka "CrossTalk"</issue>
<issue tracker="bnc" id="1176350">VUL-0: CVE-2020-25601: xen: lack of preemption in evtchn_reset() / evtchn_destroy() (XSA-344 v4)</issue>
<issue tracker="bnc" id="1176349">VUL-0: CVE-2020-25599: xen: races with evtchn_reset() (XSA-343 v4)</issue>
<issue tracker="bnc" id="1176347">VUL-0: CVE-2020-25603: xen: Missing memory barriers when accessing/allocating an event channel (XSA-340 v3)</issue>
<issue tracker="bnc" id="1176343">VUL-0: CVE-2020-25604: xen: race when migrating timers between x86 HVM vCPU-s (XSA-336 v3)</issue>
<issue tracker="bnc" id="1173378">VUL-0: CVE-2020-15565: xen: XSA-321 - insufficient cache write-back under VT-d</issue>
<issue tracker="bnc" id="1176346">VUL-0: CVE-2020-25597: xen: once valid event channels may not turn invalid (XSA-338 v4)</issue>
<issue tracker="bnc" id="1176345">VUL-0: CVE-2020-25596: xen: x86 pv guest kernel DoS via SYSENTER (XSA-339 v3)</issue>
<issue tracker="bnc" id="1175534">VUL-0: CVE-2020-14364: xen: usb: out-of-bounds r/w access issue while processing usb packets (XSA 335)</issue>
<issue tracker="cve" id="2020-25595"/>
<issue tracker="cve" id="2020-15567"/>
<issue tracker="cve" id="2020-15565"/>
<issue tracker="cve" id="2020-25604"/>
<issue tracker="cve" id="2020-0543"/>
<issue tracker="cve" id="2020-25597"/>
<issue tracker="cve" id="2020-25599"/>
<issue tracker="cve" id="2020-25600"/>
<issue tracker="cve" id="2020-25601"/>
<issue tracker="cve" id="2020-14364"/>
<issue tracker="cve" id="2020-25596"/>
<issue tracker="cve" id="2020-25603"/>
<packager>charlesa</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for xen</summary>
<description>This update for xen fixes the following issues:
- CVE-2020-25604: Fixed a race condition when migrating timers between x86
HVM vCPU-s (bsc#1176343,XSA-336)
- CVE-2020-25595: Fixed an issue where PCI passthrough code was reading back hardware registers (bsc#1176344,XSA-337)
- CVE-2020-25597: Fixed an issue where a valid event channels may not turn invalid (bsc#1176346,XSA-338)
- CVE-2020-25596: Fixed a potential denial of service in x86 pv guest kernel via SYSENTER (bsc#1176345,XSA-339)
- CVE-2020-25603: Fixed an issue due to missing barriers when accessing/allocating an event channel (bsc#1176347,XSA-340)
- CVE-2020-25600: Fixed out of bounds event channels available to 32-bit x86 domains (bsc#1176348,XSA-342)
- CVE-2020-25599: Fixed race conditions with evtchn_reset() (bsc#1176349,XSA-343)
- CVE-2020-25601: Fixed an issue due to lack of preemption in evtchn_reset() / evtchn_destroy() (bsc#1176350,XSA-344)
- CVE-2020-14364: Fixed an out-of-bounds read/write access while processing usb packets (bsc#1175534).
- CVE-2020-0543: Fixed a leak of Special Register Buffer Data Sampling (SRBDS) aka "CrossTalk" (bsc#1172205,XSA-320)
- CVE-2020-15565: Fixed an issue cache write (bsc#1173378,XSA-321).
- CVE-2020-15567: Fixed an issue with non-atomic modification of live EPT PTE (bsc#1173380,XSA-328)
</description>
</patchinfo>