Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: xen Critical XSA-476, XSA-475 Input Sanitisation Risks

fedora
Calendar Grey November 7, 2025
Dist Fedora Esm H88
Fedora 41's critical xen advisory details input sanitisation issues and permission failures on devices. Immediate actions advised.
Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

Update Information:

Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]

Change Log

* Fri Oct 24 2025 Michael Young - 4.19.3-7 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.19.3-5 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]

References

Fedora Update Notification FEDORA-2025-48dc1c8c79 2025-11-07 02:35:35.301730+00:00 Name : xen Product : Fedora 41 Version : 4.19.3 Release : 7.fc41 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-48dc1c8c79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xen
Product: Fedora 41
Version: 4.19.3
Release: 7.fc41
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here