Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2024-7c2cfa2fe5 critical: xen deadlock and data leak

fedora
Calendar Grey November 29, 2024
Dist Fedora Esm H88
Xen security notice for Fedora 40 tackling deadlock issues and potential data exposure, complete with comprehensive upgrade instructions.
Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

Update Information:

Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

Change Log

* Wed Nov 13 2024 Michael Young - 4.18.3-3 - Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] - libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819] - additional patches so above applies cleanly

References

Fedora Update Notification FEDORA-2024-7c2cfa2fe5 2024-11-29 03:47:35.523115+00:00 Name : xen Product : Fedora 40 Version : 4.18.3 Release : 3.fc40 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-7c2cfa2fe5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xen
Product: Fedora 40
Version: 4.18.3
Release: 3.fc40
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here