File _patchinfo of Package patchinfo.23693
<patchinfo incident="23693">
<issue tracker="bnc" id="1196915">VUL-0: CVE-2022-0001, CVE-2022-0002,CVE-2021-26401: xen: BHB speculation issues (XSA-398)</issue>
<issue tracker="bnc" id="1197423">VUL-0: CVE-2022-26356: xen: Racy interactions between dirty vram tracking and paging log dirty hypercalls (XSA-397)</issue>
<issue tracker="bnc" id="1197426">VUL-0: CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361: xen: IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues (XSA-400)</issue>
<issue tracker="bnc" id="1197425">VUL-0: CVE-2022-26357: xen: race in VT-d domain ID cleanup (XSA-399)</issue>
<issue tracker="cve" id="2022-26356"/>
<issue tracker="cve" id="2022-26360"/>
<issue tracker="cve" id="2022-0001"/>
<issue tracker="cve" id="2022-0002"/>
<issue tracker="cve" id="2022-26361"/>
<issue tracker="cve" id="2022-26359"/>
<issue tracker="cve" id="2021-26401"/>
<issue tracker="cve" id="2022-26357"/>
<issue tracker="cve" id="2022-26358"/>
<packager>charlesa</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for xen</summary>
<description>This update for xen fixes the following issues:
- CVE-2022-26356: Fixed potential race conditions in dirty memory tracking that
could cause a denial of service in the host (bsc#1197423).
- CVE-2022-26357: Fixed a potential race condition in memory cleanup for hosts
using VT-d IOMMU hardware, which could lead to a denial of service in the host
(bsc#1197425).
- CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361: Fixed various memory
corruption issues for hosts using VT-d or AMD-Vi IOMMU hardware. These could be
leveraged by an attacker to cause a denial of service in the host (bsc#1197426).
- CVE-2022-0001, CVE-2022-0002, CVE-2021-26401: Added BHB speculation issue
mitigations (bsc#1196915).
</description>
</patchinfo>