<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for xen</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2018:2410-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-08-17T11:42:41Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-08-17T11:42:41Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-08-17T11:42:41Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for xen</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for xen fixes the following security issues:

- CVE-2018-3646: Systems with microprocessors utilizing speculative execution
  and address translations may have allowed unauthorized disclosure of
  information residing in the L1 data cache to an attacker with local user access
  with guest OS privilege via a terminal page fault and a side-channel analysis
  (bsc#1091107, bsc#1027519).
- Incorrect MSR_DEBUGCTL handling let guests enable BTS allowing a malicious or
  buggy guest administrator can lock up the entire host (bsc#1103276)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-OpenStack-Cloud-7-2018-1664,SUSE-SLE-SAP-12-SP2-2018-1664,SUSE-SLE-SERVER-12-SP2-2018-1664,SUSE-Storage-4-2018-1664</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20182410-1/</URL>
      <Description>Link for SUSE-SU-2018:2410-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2018-August/004465.html</URL>
      <Description>E-Mail link for SUSE-SU-2018:2410-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1027519</URL>
      <Description>SUSE Bug 1027519</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1091107</URL>
      <Description>SUSE Bug 1091107</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1103276</URL>
      <Description>SUSE Bug 1103276</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-3646/</URL>
      <Description>SUSE CVE CVE-2018-3646 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 4">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 4">
        <FullProductName ProductID="SUSE Enterprise Storage 4" CPE="cpe:/o:suse:ses:4">SUSE Enterprise Storage 4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp2">SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2" CPE="cpe:/o:suse:sles_sap:12:sp2">SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 7">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 7">
        <FullProductName ProductID="SUSE OpenStack Cloud 7" CPE="cpe:/o:suse:suse-openstack-cloud:7">SUSE OpenStack Cloud 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="xen-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-4.7.6_04-43.39.1">xen-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-doc-html-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-doc-html-4.7.6_04-43.39.1">xen-doc-html-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-libs-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-libs-4.7.6_04-43.39.1">xen-libs-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-libs-32bit-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-libs-32bit-4.7.6_04-43.39.1">xen-libs-32bit-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-tools-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-tools-4.7.6_04-43.39.1">xen-tools-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-tools-domU-4.7.6_04-43.39.1">
      <FullProductName ProductID="xen-tools-domU-4.7.6_04-43.39.1">xen-tools-domU-4.7.6_04-43.39.1</FullProductName>
    </Branch>
    <Relationship ProductReference="xen-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-4.7.6_04-43.39.1">xen-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-doc-html-4.7.6_04-43.39.1">xen-doc-html-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-libs-4.7.6_04-43.39.1">xen-libs-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-libs-32bit-4.7.6_04-43.39.1">xen-libs-32bit-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-tools-4.7.6_04-43.39.1">xen-tools-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:xen-tools-domU-4.7.6_04-43.39.1">xen-tools-domU-4.7.6_04-43.39.1 as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-4.7.6_04-43.39.1">xen-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-doc-html-4.7.6_04-43.39.1">xen-doc-html-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-libs-4.7.6_04-43.39.1">xen-libs-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-libs-32bit-4.7.6_04-43.39.1">xen-libs-32bit-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-tools-4.7.6_04-43.39.1">xen-tools-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2-LTSS:xen-tools-domU-4.7.6_04-43.39.1">xen-tools-domU-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server 12 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-4.7.6_04-43.39.1">xen-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-doc-html-4.7.6_04-43.39.1">xen-doc-html-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-libs-4.7.6_04-43.39.1">xen-libs-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-libs-32bit-4.7.6_04-43.39.1">xen-libs-32bit-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-tools-4.7.6_04-43.39.1">xen-tools-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-tools-domU-4.7.6_04-43.39.1">xen-tools-domU-4.7.6_04-43.39.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-4.7.6_04-43.39.1">xen-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-doc-html-4.7.6_04-43.39.1">xen-doc-html-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-libs-4.7.6_04-43.39.1">xen-libs-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-libs-32bit-4.7.6_04-43.39.1">xen-libs-32bit-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-tools-4.7.6_04-43.39.1">xen-tools-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.7.6_04-43.39.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:xen-tools-domU-4.7.6_04-43.39.1">xen-tools-domU-4.7.6_04-43.39.1 as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.</Note>
    </Notes>
    <CVE>CVE-2018-3646</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Enterprise Storage 4:xen-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:xen-doc-html-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:xen-libs-32bit-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:xen-libs-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:xen-tools-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Enterprise Storage 4:xen-tools-domU-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-doc-html-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-libs-32bit-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-libs-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-tools-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2-LTSS:xen-tools-domU-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-doc-html-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-libs-32bit-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-libs-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-tools-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:xen-tools-domU-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-doc-html-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-libs-32bit-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-libs-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-tools-4.7.6_04-43.39.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:xen-tools-domU-4.7.6_04-43.39.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20182410-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-3646.html</URL>
        <Description>CVE-2018-3646</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087078</URL>
        <Description>SUSE Bug 1087078</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087081</URL>
        <Description>SUSE Bug 1087081</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1089343</URL>
        <Description>SUSE Bug 1089343</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1091107</URL>
        <Description>SUSE Bug 1091107</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1099306</URL>
        <Description>SUSE Bug 1099306</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104365</URL>
        <Description>SUSE Bug 1104365</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1104894</URL>
        <Description>SUSE Bug 1104894</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1106548</URL>
        <Description>SUSE Bug 1106548</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1113534</URL>
        <Description>SUSE Bug 1113534</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136865</URL>
        <Description>SUSE Bug 1136865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201877</URL>
        <Description>SUSE Bug 1201877</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
