SB2022020425 - SUSE update for xen
Published: February 4, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Integer underflow (CVE-ID: CVE-2022-23034)
The vulnerability allows a local user can perform a denial of service attack.
The vulnerability exists due to integer underflow when unmapping a grant to address XSA-380. A local user can request two forms of mappings to perform a denial of service attack.
2) Incomplete cleanup (CVE-ID: CVE-2022-23035)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to insufficient cleanup of passed-through device IRQs. An attacker with physical access can cause a Denial of Service (DoS) and escalate privileges on the system.
Remediation
Install update from vendor's website.