File _patchinfo of Package patchinfo.23693

<patchinfo incident="23693">
  <issue tracker="bnc" id="1196915">VUL-0: CVE-2022-0001, CVE-2022-0002,CVE-2021-26401: xen: BHB speculation issues (XSA-398)</issue>
  <issue tracker="bnc" id="1197423">VUL-0: CVE-2022-26356: xen: Racy interactions between dirty vram tracking and paging log dirty hypercalls (XSA-397)</issue>
  <issue tracker="bnc" id="1197426">VUL-0: CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361: xen:  IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues (XSA-400)</issue>
  <issue tracker="bnc" id="1197425">VUL-0: CVE-2022-26357: xen: race in VT-d domain ID cleanup (XSA-399)</issue>
  <issue tracker="cve" id="2022-26356"/>
  <issue tracker="cve" id="2022-26360"/>
  <issue tracker="cve" id="2022-0001"/>
  <issue tracker="cve" id="2022-0002"/>
  <issue tracker="cve" id="2022-26361"/>
  <issue tracker="cve" id="2022-26359"/>
  <issue tracker="cve" id="2021-26401"/>
  <issue tracker="cve" id="2022-26357"/>
  <issue tracker="cve" id="2022-26358"/>
  <packager>charlesa</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for xen</summary>
  <description>This update for xen fixes the following issues:

- CVE-2022-26356: Fixed potential race conditions in dirty memory tracking that
  could cause a denial of service in the host (bsc#1197423).
- CVE-2022-26357: Fixed a potential race condition in memory cleanup for hosts
  using VT-d IOMMU hardware, which could lead to a denial of service in the host
  (bsc#1197425).
- CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361: Fixed various memory
  corruption issues for hosts using VT-d or AMD-Vi IOMMU hardware. These could be
  leveraged by an attacker to cause a denial of service in the host (bsc#1197426).
- CVE-2022-0001, CVE-2022-0002, CVE-2021-26401: Added BHB speculation issue
  mitigations (bsc#1196915).
</description>
</patchinfo>
openSUSE Build Service is sponsored by