SUSE-SU-2026:3409-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263409-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3409-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3409-1
Upstream
CVE (15)
  • CVE-2026-42493
  • CVE-2026-42494
  • CVE-2026-42495
  • CVE-2026-62423
  • CVE-2026-62424
  • CVE-2026-62425
  • CVE-2026-62426
  • CVE-2026-62427
  • CVE-2026-62428
  • CVE-2026-62429
  • CVE-2026-62430
  • CVE-2026-62431
  • CVE-2026-62432
  • CVE-2026-62433
  • CVE-2026-62434
Related
Published
2026-07-29T11:18:18Z
Modified
2026-07-30T17:15:09Z
Summary
Security update for xen
Details

This update for xen fixes the following issues

  • CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
  • CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530).
  • CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531).
  • CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
  • CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534).
  • CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
  • CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
  • CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
  • CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
  • CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
  • pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
References

Affected packages

SUSE:Linux Enterprise Server 15 SP6-LTSS / xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.18.5_20-150600.3.53.3

Ecosystem specific

{
    "binaries":  [
        {
            "xen":  "4.18.5_20-150600.3.53.3",
            "xen-devel":  "4.18.5_20-150600.3.53.3",
            "xen-libs":  "4.18.5_20-150600.3.53.3",
            "xen-tools":  "4.18.5_20-150600.3.53.3",
            "xen-tools-domU":  "4.18.5_20-150600.3.53.3",
            "xen-tools-xendomains-wait-disk":  "4.18.5_20-150600.3.53.3"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3409-1.json"

SUSE:Linux Enterprise Server for SAP Applications 15 SP6 / xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.18.5_20-150600.3.53.3

Ecosystem specific

{
    "binaries":  [
        {
            "xen":  "4.18.5_20-150600.3.53.3",
            "xen-devel":  "4.18.5_20-150600.3.53.3",
            "xen-libs":  "4.18.5_20-150600.3.53.3",
            "xen-tools":  "4.18.5_20-150600.3.53.3",
            "xen-tools-domU":  "4.18.5_20-150600.3.53.3",
            "xen-tools-xendomains-wait-disk":  "4.18.5_20-150600.3.53.3"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3409-1.json"