Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2017-9374: xen: usb: ehci host memory leakage during hotunplug | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Johannes Segitz <jsegitz> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P3 - Medium | CC: | carnold, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/186308/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Bug Depends on: | 1043073 | ||
Bug Blocks: |
Description
Johannes Segitz
2017-06-07 08:36:12 UTC
SUSE-SU-2017:1770-1: An update that solves 6 vulnerabilities and has 12 fixes is now available. Category: security (important) Bug References: 1014136,1026236,1027519,1031460,1032148,1034845,1036470,1037243,1042160,1042863,1042882,1042893,1042915,1042924,1042931,1042938,1043074,1043297 CVE References: CVE-2017-8112,CVE-2017-8309,CVE-2017-8905,CVE-2017-9330,CVE-2017-9374,CVE-2017-9503 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): xen-4.4.4_20-60.3 SUSE Linux Enterprise Server 11-SP4 (src): xen-4.4.4_20-60.3 SUSE Linux Enterprise Debuginfo 11-SP4 (src): xen-4.4.4_20-60.3 SUSE-SU-2017:1795-1: An update that solves 16 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1014136,1026236,1027519,1031460,1032148,1034845,1036470,1037243,1042160,1042863,1042882,1042893,1042915,1042924,1042931,1042938,1043074,1043297 CVE References: CVE-2017-10911,CVE-2017-10912,CVE-2017-10913,CVE-2017-10914,CVE-2017-10915,CVE-2017-10917,CVE-2017-10918,CVE-2017-10920,CVE-2017-10921,CVE-2017-10922,CVE-2017-8112,CVE-2017-8309,CVE-2017-8905,CVE-2017-9330,CVE-2017-9374,CVE-2017-9503 Sources used: SUSE Linux Enterprise Server for SAP 12 (src): xen-4.4.4_21-22.42.1 SUSE Linux Enterprise Server 12-LTSS (src): xen-4.4.4_21-22.42.1 SUSE-SU-2017:1812-1: An update that solves 17 vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1014136,1026236,1027519,1031460,1034845,1036470,1037243,1042160,1042863,1042882,1042893,1042915,1042923,1042924,1042931,1042938,1043074,1043297 CVE References: CVE-2017-10911,CVE-2017-10912,CVE-2017-10913,CVE-2017-10914,CVE-2017-10915,CVE-2017-10916,CVE-2017-10917,CVE-2017-10918,CVE-2017-10920,CVE-2017-10921,CVE-2017-10922,CVE-2017-8112,CVE-2017-8309,CVE-2017-8905,CVE-2017-9330,CVE-2017-9374,CVE-2017-9503 Sources used: SUSE OpenStack Cloud 6 (src): xen-4.5.5_12-22.18.1 SUSE Linux Enterprise Server for SAP 12-SP1 (src): xen-4.5.5_12-22.18.1 SUSE Linux Enterprise Server 12-SP1-LTSS (src): xen-4.5.5_12-22.18.1 This patch is for ehci (usb 2.0) found in the upstream qemu. However, the version of the xen upstream qemu in SLE11 SP3 is too old and a fprintf statement issued in the usb ehci initialization code says, "*** EHCI support is under development ***\n" So nothing usable that can be patched in SLE11 SP3 and older. released |