SuSE 10 Security Update : Xen (ZYPP Patch Number 7547)
Medium Nessus Plugin ID 57265
SynopsisThe remote SuSE 10 host is missing a security-related patch.
DescriptionThis collective June/2011 Update for Xen provides the following fixes :
- Xen does not properly check the upper boundary of user-supplied data in the get_free_port() function when getting a new event channel port. A local user on the guest operating system can exploit this flaw to cause denial of service conditions or potentially gain elevated privileges. (CVE-2011-1166)
- 654798: Fix race between hotplug scripts writing to xenstore and xend registering a watch for the write.
- 684297: HVM taking too long to dump vmcore
- 688757: Fix kernel panic on fully virtualized setup
- 658413: Fix root drive search on SLES 10-SP3 HVM guest
- 675363: Random lockups with kernel-xen related to graphics
SolutionApply ZYPP patch number 7547.