{"id":"SUSE-SU-2015:1045-1","summary":"Security update for Xen","details":"\nXen was updated to fix seven security vulnerabilities:\n\n    * CVE-2015-4103: Potential unintended writes to host MSI message data\n      field via qemu. (XSA-128, bnc#931625)\n    * CVE-2015-4104: PCI MSI mask bits inadvertently exposed to guests.\n      (XSA-129, bnc#931626)\n    * CVE-2015-4105: Guest triggerable qemu MSI-X pass-through error\n      messages. (XSA-130, bnc#931627)\n    * CVE-2015-4106: Unmediated PCI register access in qemu. (XSA-131,\n      bnc#931628)\n    * CVE-2015-4163: GNTTABOP_swap_grant_ref operation misbehavior.\n      (XSA-134, bnc#932790)\n    * CVE-2015-3209: Heap overflow in qemu pcnet controller allowing guest\n      to host escape. (XSA-135, bnc#932770)\n    * CVE-2015-4164: DoS through iret hypercall handler. (XSA-136,\n      bnc#932996)\n\nSecurity Issues:\n\n    * CVE-2015-4103\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4103\u003e\n    * CVE-2015-4104\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4104\u003e\n    * CVE-2015-4105\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4105\u003e\n    * CVE-2015-4106\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4106\u003e\n    * CVE-2015-4163\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4163\u003e\n    * CVE-2015-4164\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4164\u003e\n    * CVE-2015-3209\n      \u003chttp://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3209\u003e\n\n","modified":"2026-03-11T06:06:15.594961Z","published":"2015-06-05T12:53:19Z","related":["CVE-2015-3209","CVE-2015-4103","CVE-2015-4104","CVE-2015-4105","CVE-2015-4106","CVE-2015-4163","CVE-2015-4164"],"upstream":["CVE-2015-3209","CVE-2015-4103","CVE-2015-4104","CVE-2015-4105","CVE-2015-4106","CVE-2015-4163","CVE-2015-4164"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151045-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/931625"},{"type":"REPORT","url":"https://bugzilla.suse.com/931626"},{"type":"REPORT","url":"https://bugzilla.suse.com/931627"},{"type":"REPORT","url":"https://bugzilla.suse.com/931628"},{"type":"REPORT","url":"https://bugzilla.suse.com/932770"},{"type":"REPORT","url":"https://bugzilla.suse.com/932790"},{"type":"REPORT","url":"https://bugzilla.suse.com/932996"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-4164"}],"schema_version":"1.7.5"}