SUSE-SU-2026:4090-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264090-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4090-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4090-1
Upstream
CVE (18)
  • CVE-2026-42493
  • CVE-2026-42494
  • CVE-2026-42495
  • CVE-2026-62423
  • CVE-2026-62424
  • CVE-2026-62425
  • CVE-2026-62426
  • CVE-2026-62427
  • CVE-2026-62428
  • CVE-2026-62429
  • CVE-2026-62430
  • CVE-2026-62431
  • CVE-2026-62432
  • CVE-2026-62433
  • CVE-2026-62434
  • CVE-2026-62437
  • CVE-2026-79602
  • CVE-2026-79603
Related
Published
2026-09-08T12:26:56Z
Modified
2026-09-13T18:23:20Z
Summary
Security update for xen
Details

This update for xen fixes the following issues:

Update to version 4.20.3 (jsc#PED-8907).

Security issues fixed:

  • CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
  • CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530).
  • CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531).
  • CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
  • CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534).
  • CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
  • CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
  • CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
  • CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
  • CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
  • CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838).
  • CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839).
  • CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841).
  • pygrub is only supported in de-privileged mode (bsc#1271947).

Non security issue fixed:

  • Xen: Missing upstream bug fixes (bsc#1027519).
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.20.4_04-150700.3.46.1

Ecosystem specific

{
    "binaries":  [
        {
            "xen-libs":  "4.20.4_04-150700.3.46.1",
            "xen-tools-domU":  "4.20.4_04-150700.3.46.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4090-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
xen

Package

Name
xen
Purl
pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.20.4_04-150700.3.46.1

Ecosystem specific

{
    "binaries":  [
        {
            "xen":  "4.20.4_04-150700.3.46.1",
            "xen-devel":  "4.20.4_04-150700.3.46.1",
            "xen-tools":  "4.20.4_04-150700.3.46.1",
            "xen-tools-xendomains-wait-disk":  "4.20.4_04-150700.3.46.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4090-1.json"