File _patchinfo of Package patchinfo.17647

<patchinfo incident="17647">
  <issue tracker="bnc" id="1179501">VUL-0: EMBARGOED: CVE-2020-29484: xen: xenstore: guests can crash xenstored via watchs (XSA-324 v2)</issue>
  <issue tracker="bnc" id="1027519">Xen: Missing upstream bug fixes</issue>
  <issue tracker="bnc" id="1179496">VUL-0: EMBARGOED: CVE-2020-29480: xen: xenstore: watch notifications lacking permission checks (XSA-115 v3)</issue>
  <issue tracker="bnc" id="1179514">VUL-0: EMBARGOED: CVE-2020-29570: xen: FIFO event channels control block related ordering (XSA-358 v3)</issue>
  <issue tracker="bnc" id="1179506">VUL-0: EMBARGOED: CVE-2020-29566: xen: undue recursion in x86 HVM context switch code (XSA-348 v2)</issue>
  <issue tracker="bnc" id="1179498">VUL-0: EMBARGOED: CVE-2020-29481: xen: xenstore: new domains inheriting existing node permissions (XSA-322 v3)</issue>
  <issue tracker="bnc" id="1179516">VUL-0: EMBARGOED: CVE-2020-29571: xen: FIFO event channels control structure ordering (XSA-359 v2)</issue>
  <issue tracker="bnc" id="1179502">VUL-0: EMBARGOED: CVE-2020-29483: xen: xenstore: guests can disturb domain cleanup (XSA-325 v2)</issue>
  <issue tracker="bnc" id="1176782">L3: xl dump-core shows missing nr_pages during core. If maxmem and current are the same the issue doesn't happen</issue>
  <issue tracker="cve" id="2020-29571"/>
  <issue tracker="cve" id="2020-29484"/>
  <issue tracker="cve" id="2020-29480"/>
  <issue tracker="cve" id="2020-29483"/>
  <issue tracker="cve" id="2020-29570"/>
  <issue tracker="cve" id="2020-29566"/>
  <issue tracker="cve" id="2020-29481"/>
  <packager>charlesa</packager>
  <rating>moderate</rating>
  <category>security</category>
  <summary>Security update for xen</summary>
  <description>This update for xen fixes the following issues:

- CVE-2020-29480: Fixed an issue which could have allowed leak of non-sensitive data to administrator guests (bsc#117949 XSA-115).
- CVE-2020-29481: Fixed an issue which could have allowd to new domains to inherit existing node permissions (bsc#1179498 XSA-322). 
- CVE-2020-29483: Fixed an issue where guests could disturb domain cleanup (bsc#1179502 XSA-325).
- CVE-2020-29484: Fixed an issue where guests could crash xenstored via watchs (bsc#1179501 XSA-324). 
- CVE-2020-29566: Fixed an undue recursion in x86 HVM context switch code (bsc#1179506 XSA-348).
- CVE-2020-29570: Fixed an issue where FIFO event channels control block related ordering (bsc#1179514 XSA-358).
- CVE-2020-29571: Fixed an issue where FIFO event channels control structure ordering (bsc#1179516 XSA-359).
- Fixed an issue where dump-core shows missing nr_pages during core (bsc#1176782).
- Multiple other bugs (bsc#1027519)
</description>
</patchinfo>
openSUSE Build Service is sponsored by