Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
This update for xen fixes the following issues
* CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
* CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425:
buffer overruns in libfsimage iso9660 handling (bsc#1271530).
* CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse
* CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
* CVE-2026-62429: vNUMA domain cleanup may race other operations
* CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
* CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
* CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
* CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
* CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
* pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
## Special Instructions...
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3423=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3423=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3423=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3423=1
zypper in -t patch SUSE-2026-3423=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3423=1
* openSUSE Leap 15.5 (x86_64)
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-libs-32bit-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-doc-html-4.17.6_14-150500.3.76.3
* xen-libs-32bit-4.17.6_14-150500.3.76.3
* openSUSE Leap 15.5 (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* openSUSE Leap 15.5 (i586 x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
