x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0da80aa623 2024-03-14 01:38:51.491768 -------------------------------------------------------------------------------- Name : xen Product : Fedora 38 Version : 4.17.2 Release : 7.fc38 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 27 2024 Michael Young - 4.17.2-7 - x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2266325 - CVE-2023-46841 xen: x86 shadow stack vs exceptions from emulation stubs https://bugzilla.redhat.com/show_bug.cgi?id=2266325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0da80aa623' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list--
x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aca9ed1eb1 2024-03-14 01:07:19.210138 -------------------------------------------------------------------------------- Name : xen Product : Fedora 39 Version : 4.17.2 Release : 7.fc39 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 27 2024 Michael Young - 4.17.2-7 - x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2266325 - CVE-2023-46841 xen: x86 shadow stack vs exceptions from emulation stubs https://bugzilla.redhat.com/show_bug.cgi?id=2266325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aca9ed1eb1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list--
Update rust-vmm components and their consumers to address CVE-2023-50711. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-04877592b7 2024-02-10 01:24:59.648730 -------------------------------------------------------------------------------- Name : rust-vm-superio Product : Fedora 39 Version : 0.7.0 Release : 4.fc39 URL : Summary : Emulation for legacy devices Description : Emulation for legacy devices. -------------------------------------------------------------------------------- Update Information: Update rust-vmm components and their consumers to address CVE-2023-50711 -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 27 2024 Fedora Release Engineering - 0.7.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Tue Jan 9 2024 David Michael - 0.7.0-3 - Bump vmm-sys-util to 0.12 for CVE-2023-50711 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-04877592b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-374389c196 2017-05-12 14:08:49.129102 --------------------------------------------------------------------------------Name : qemu Product : Fedora 24 Version : 2.6.2 Release : 8.fc24 URL : https://www.qemu.org/ Summary : QEMU is a FAST! processor emulator Description : QEMU is a generic and open source processor emulator which achieves a good emulation speed by using dynamic translation. QEMU has two operating modes: * Full system emulation. In this mode, QEMU emulates a full system (for example a PC), including a processor and various peripherials. It can be used to launch different Operating Systems without rebooting the PC or to debug system code. * User mode emulation. In this mode, QEMU can launch Linux processes compiled for one CPU on another CPU. As QEMU requires no host kernel patches to run, it is safe and easy to use. --------------------------------------------------------------------------------Update Information: * Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161) --------------------------------------------------------------------------------References: [ 1 ] Bug #1384874 - CVE-2016-8667 Qemu: hw: dma: divide by zero error in set_next_tick https://bugzilla.redhat.com/show_bug.cgi?id=1384874 [ 2 ] Bug #1416157 - CVE-2017-5579 Qemu: serial: host memory leakage 16550A UART emulation https://bugzilla.redhat.com/show_bug.cgi?id=1416157 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade qemu' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that the e1000 emulation code in QEMU does not enforce frame size limits in the same way as the real hardware does. This could trigger buffer overflows in the guest operating system driver for that network card, assuming that the host system does not . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2608-1
Get the latest Linux and open source security news straight to your inbox.