SUSE-SU-2026:3451-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263451-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3451-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3451-1
Upstream
CVE (14)
  • CVE-2026-42493
  • CVE-2026-42494
  • CVE-2026-42495
  • CVE-2026-62423
  • CVE-2026-62424
  • CVE-2026-62425
  • CVE-2026-62426
  • CVE-2026-62427
  • CVE-2026-62428
  • CVE-2026-62429
  • CVE-2026-62430
  • CVE-2026-62432
  • CVE-2026-62433
  • CVE-2026-62434
Related
Published
2026-08-03T11:33:31Z
Modified
2026-08-04T11:45:06Z
Summary
Security update for xen
Details

This update for xen fixes the following issues

  • CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
  • CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530).
  • CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531).
  • CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
  • CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534).
  • CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
  • CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
  • CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
  • CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
  • pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.12.4_72-3.148.4

Ecosystem specific

{
    "binaries":  [
        {
            "xen":  "4.12.4_72-3.148.4",
            "xen-devel":  "4.12.4_72-3.148.4",
            "xen-doc-html":  "4.12.4_72-3.148.4",
            "xen-libs":  "4.12.4_72-3.148.4",
            "xen-libs-32bit":  "4.12.4_72-3.148.4",
            "xen-tools":  "4.12.4_72-3.148.4",
            "xen-tools-domU":  "4.12.4_72-3.148.4"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3451-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.12.4_72-3.148.4

Ecosystem specific

{
    "binaries":  [
        {
            "xen":  "4.12.4_72-3.148.4",
            "xen-devel":  "4.12.4_72-3.148.4",
            "xen-doc-html":  "4.12.4_72-3.148.4",
            "xen-libs":  "4.12.4_72-3.148.4",
            "xen-libs-32bit":  "4.12.4_72-3.148.4",
            "xen-tools":  "4.12.4_72-3.148.4",
            "xen-tools-domU":  "4.12.4_72-3.148.4"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3451-1.json"