Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 30: FEDORA-2020-cbc3149753 Critical: Xen Security Update

fedora
Calendar Grey May 10, 2020
Dist Fedora Esm H88
Addressing critical security issues in Fedora 30's Xen. Install updates for enhanced protection against exploitation.
update to 4.11.4 ---- multiple xenoprof issues [XSA-313, CVE-2020-11740, CVE-2020-11741] (#1823912, #1823914) Missing memory barriers in read-write unlock paths [XSA-314, CVE-2020-...

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

update to 4.11.4 ---- multiple xenoprof issues [XSA-313, CVE-2020-11740,

CVE-2020-11741] (#1823912, #1823914) Missing memory barriers in read-write

unlock paths [XSA-314, CVE-2020-11739] (#1823784) Bad error path in

GNTTABOP_map_grant [XSA-316, CVE-2020-11743] (#1823926) Bad continuation

handling in GNTTABOP_copy [XSA-318, CVE-2020-11742] (#1823943)

* Sat Apr 25 2020 Michael Young - 4.11.4-1

- update to 4.11.4

remove patches now fixed upstream

adjust xen.use.fedora.ipxe.patch

* Wed Apr 15 2020 Michael Young - 4.11.3-4

- multiple xenoprof issues [XSA-313, CVE-2020-11740, CVE-2020-11741]

(#1823912, #1823914)

- Missing memory barriers in read-write unlock paths [XSA-314,

CVE-2020-11739] (#1823784)

- Bad error path in GNTTABOP_map_grant [XSA-316, CVE-2020-11743] (#1823926)

- Bad continuation handling in GNTTABOP_copy [XSA-318, CVE-2020-11742]

(#1823943)

[ 1 ] Bug #1823783 - CVE-2020-11739 xen: missing memory barriers in read-write unlock paths (XSA-314)

https://bugzilla.redhat.com/show_bug.cgi?id=1823783

[ 2 ] Bug #1823911 - CVE-2020-11740 xen: xenoprof issue allows guest OS users without active profiling to obtain sensitive information about other guests (XSA-313)

https://bugzilla.redhat.com/show_bug.cgi?id=1823911

[ 3 ] Bug #1823913 - CVE-2020-11741 xen: xenoprof issue allows guest OS users with active profiling to obtain sensitive information about other guests (XSA-313)

https://bugzilla.redhat.com/show_bug.cgi?id=1823913

[ 4 ] Bug #1823925 - CVE-2020-11743 xen: bad error path in GNTTABOP_map_grant (XSA-316)

https://bugzilla.redhat.com/show_bug.cgi?id=1823925

[ 5 ] Bug #1823942 - CVE-2020-11742 xen: bad continuation handling in GNTTABOP_copy (XSA-318)

https://bugzilla.redhat.com/show_bug.cgi?id=1823942

su -c 'dnf upgrade --advisory FEDORA-2020-cbc3149753' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 4.11.4
Release: 1.fc30
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here