MGASA-2024-0115 - Updated xen packages fix security vulnerabilities

Publication date: 10 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0115.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-46841,
     CVE-2023-28746,
     CVE-2024-2193

x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841)
x86: Register File Data Sampling. (CVE-2023-28746)
GhostRace: Speculative Race Conditions. (CVE-2024-2193)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32905
- https://www.openwall.com/lists/oss-security/2024/02/27/2
- https://www.openwall.com/lists/oss-security/2024/03/12/13
- https://www.openwall.com/lists/oss-security/2024/03/12/14
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46841
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2193

SRPMS:
- 9/core/xen-4.17.3-1.1.mga9

Mageia 2024-0115: xen security update

x86: shadow stack vs exceptions from emulation stubs

Summary

x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841) x86: Register File Data Sampling. (CVE-2023-28746) GhostRace: Speculative Race Conditions. (CVE-2024-2193)

References

- https://bugs.mageia.org/show_bug.cgi?id=32905

- https://www.openwall.com/lists/oss-security/2024/02/27/2

- https://www.openwall.com/lists/oss-security/2024/03/12/13

- https://www.openwall.com/lists/oss-security/2024/03/12/14

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46841

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28746

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2193

Resolution

MGASA-2024-0115 - Updated xen packages fix security vulnerabilities

SRPMS

- 9/core/xen-4.17.3-1.1.mga9

Severity
Publication date: 10 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0115.html
Type: security
CVE: CVE-2023-46841, CVE-2023-28746, CVE-2024-2193

Related News