Linux: display frontend "be-alloc" mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-4c819bf1ad 2021-02-26 01:08:09.396907 --------------------------------------------------------------------------------Name : xen Product : Fedora 32 Version : 4.13.2 Release : 7.fc32 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: Linux: display frontend "be-alloc" mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547) --------------------------------------------------------------------------------ChangeLog: * Wed Feb 17 2021 Michael Young - 4.13.2-7 - Linux: display frontend "be-alloc" mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) - arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547) --------------------------------------------------------------------------------References: [ 1 ] Bug #1929546 - CVE-2021-26933 xen: arm: The cache may not be cleaned for newly allocated scrubbed pages https://bugzilla.redhat.com/show_bug.cgi?id=1929546 [ 2 ] Bug #1929548 - CVE-2021-26934 xen: Linux: display frontend "be-alloc" mode is unsupported https://bugzilla.redhat.com/show_bug.cgi?id=1929548 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2021-4c819bf1ad' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
* Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-374389c196 2017-05-12 14:08:49.129102 --------------------------------------------------------------------------------Name : qemu Product : Fedora 24 Version : 2.6.2 Release : 8.fc24 URL : https://www.qemu.org/ Summary : QEMU is a FAST! processor emulator Description : QEMU is a generic and open source processor emulator which achieves a good emulation speed by using dynamic translation. QEMU has two operating modes: * Full system emulation. In this mode, QEMU emulates a full system (for example a PC), including a processor and various peripherials. It can be used to launch different Operating Systems without rebooting the PC or to debug system code. * User mode emulation. In this mode, QEMU can launch Linux processes compiled for one CPU on another CPU. As QEMU requires no host kernel patches to run, it is safe and easy to use. --------------------------------------------------------------------------------Update Information: * Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161) --------------------------------------------------------------------------------References: [ 1 ] Bug #1384874 - CVE-2016-8667 Qemu: hw: dma: divide by zero error in set_next_tick https://bugzilla.redhat.com/show_bug.cgi?id=1384874 [ 2 ] Bug #1416157 - CVE-2017-5579 Qemu: serial: host memory leakage 16550A UART emulation https://bugzilla.redhat.com/show_bug.cgi?id=1416157 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade qemu' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that the patch to fix CVE-2016-6635 added a function already present in the code, preventing the website to display completely. The package has been updated to fix this regression. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3681-2
The latest security update, DSA-2464-1, for Icedove, Debian's version of the Mozilla Thunderbird mail client, contained a regression: the removal of UTF-7 support resulted in incorrect display of IMAP folder names. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2464-2
Get the latest Linux and open source security news straight to your inbox.