Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9: MGASA-2024-0115 Critical: Xen Security Vulnerabilities

mageia
Calendar Grey April 10, 2024
Dist Mageia Esm H88
Enhanced xen packages released to resolve significant security vulnerabilities in Mageia 9. Announcement date is April 10, 2024. Further information included.
x86: shadow stack vs exceptions from emulation stubs

Summary

x86: shadow stack vs exceptions from emulation stubs. (CVE-2023-46841) x86: Register File Data Sampling. (CVE-2023-28746) GhostRace: Speculative Race Conditions. (CVE-2024-2193)

References

- https://bugs.mageia.org/show_bug.cgi?id=32905

- https://www.openwall.com/lists/oss-security/2024/02/27/2

- https://www.openwall.com/lists/oss-security/2024/03/12/13

- https://www.openwall.com/lists/oss-security/2024/03/12/14

- https://www.cve.org/CVERecord?id=CVE-2023-46841

- https://www.cve.org/CVERecord?id=CVE-2023-28746

- https://www.cve.org/CVERecord?id=CVE-2024-2193

Resolution

SRPMS

- 9/core/xen-4.17.3-1.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0115.html
Type: security
CVE: CVE-2023-46841, CVE-2023-28746, CVE-2024-2193

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here