xen 4.11.4+57-g41a822c392-2 source package in Debian

Changelog

xen (4.11.4+57-g41a822c392-2) buster-security; urgency=high

  * Apply security fixes for the following issues:
    - oxenstored: permissions not checked on root node
      XSA-353 (CVE-2020-29479)
    - xenstore watch notifications lacking permission checks
      XSA-115 (CVE-2020-29480)
    - Xenstore: new domains inheriting existing node permissions
      XSA-322 (CVE-2020-29481)
    - Xenstore: wrong path length check
      XSA-323 (CVE-2020-29482)
    - Xenstore: guests can crash xenstored via watchs
      XSA-324 (CVE-2020-29484)
    - Xenstore: guests can disturb domain cleanup
      XSA-325 (CVE-2020-29483)
    - oxenstored memory leak in reset_watches
      XSA-330 (CVE-2020-29485)
    - oxenstored: node ownership can be changed by unprivileged clients
      XSA-352 (CVE-2020-29486)
    - undue recursion in x86 HVM context switch code
      XSA-348 (CVE-2020-29566)
    - FIFO event channels control block related ordering
      XSA-358 (CVE-2020-29570)
    - FIFO event channels control structure ordering
      XSA-359 (CVE-2020-29571)
  * Note that the following XSA are not listed, because...
    - XSA-349 and XSA-350 have patches for the Linux kernel
    - XSA-354 has patches for the XAPI toolstack
    - XSA-356 only applies to Xen 4.14

 -- Hans van Kranenburg <email address hidden>  Fri, 11 Dec 2020 22:10:09 +0100

Upload details

Uploaded by:
Debian Xen Team
Uploaded to:
Buster
Original maintainer:
Debian Xen Team
Architectures:
amd64 arm64 armhf i386 all
Section:
kernel
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
xen_4.11.4+57-g41a822c392-2.dsc 4.0 KiB 5346213e9f203d64a426f5cfda94669c2cbe3c8d645620740053a49781e91e5d
xen_4.11.4+57-g41a822c392.orig.tar.xz 4.1 MiB 05907904c6d250afc96ec26c048513c59b55f40d6a44a6b297ca78204b3f5649
xen_4.11.4+57-g41a822c392-2.debian.tar.xz 161.4 KiB 1b6bbf5dc05a11d28509b1f25cb96e256b91ce48b4c3667e77194e783f25ed88

No changes file available.

Binary packages built by this source