Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks. For the stable distribution (bullseye), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5272-1
x86: MMIO Stale Data vulnerabilities [XSA-404, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-925fc688c1 2022-07-01 01:05:36.532438 --------------------------------------------------------------------------------Name : xen Product : Fedora 36 Version : 4.16.1 Release : 4.fc36 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: x86: MMIO Stale Data vulnerabilities [XSA-404, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166] --------------------------------------------------------------------------------ChangeLog: * Tue Jun 21 2022 Michael Young - 4.16.1-4 - x86: MMIO Stale Data vulnerabilities [XSA-404, CVE-2022-21123, CVE-2022-21125, CVE-2022-21166] * Mon Jun 13 2022 Python Maint - 4.16.1-3 - Rebuilt for Python 3.11 (F37 build only) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-925fc688c1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
update to xen-4.14.5 ---- Racy interactions between dirty vram tracking and paging log dirty hypercalls [XSA-397, CVE-2022-26356] race in VT-d domain ID cleanup [XSA-399, CVE-2022-26357] IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues [XSA-400, CVE-2022-26358, CVE-2022-26359, CVE-2022-26360, CVE-2022-26361]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-64b2c02d29 2022-05-02 07:30:26.553347 --------------------------------------------------------------------------------Name : xen Product : Fedora 34 Version : 4.14.5 Release : 1.fc34 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: update to xen-4.14.5 ---- Racy interactions between dirty vram tracking and paging log dirty hypercalls [XSA-397, CVE-2022-26356] race in VT-d domain ID cleanup [XSA-399, CVE-2022-26357] IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues [XSA-400, CVE-2022-26358, CVE-2022-26359, CVE-2022-26360, CVE-2022-26361] --------------------------------------------------------------------------------ChangeLog: * Fri Apr 15 2022 Michael Young - 4.14.5-1 - update to xen-4.14.5 remove or adjust patches now included or superceded upstream * Wed Apr 6 2022 Michael Young - 4.14.4-3 - Racy interactions between dirty vram tracking and paging log dirty hypercalls [XSA-397, CVE-2022-26356] - race in VT-d domain ID cleanup [XSA-399, CVE-2022-26357] - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues [XSA-400, CVE-2022-26358, CVE-2022-26359, CVE-2022-26360, CVE-2022-26361] --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2022-64b2c02d29' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks. For the stable distribution (bullseye), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5117-1
Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380 stop editing grub files in /boot/efi/EFI/fedora on Fedora 34. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-11577e5229 2021-09-16 19:13:47.410742 --------------------------------------------------------------------------------Name : xen Product : Fedora 34 Version : 4.14.2 Release : 4.fc34 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380 stop editing grub files in /boot/efi/EFI/fedora on Fedora 34 --------------------------------------------------------------------------------ChangeLog: * Wed Sep 8 2021 Michael Young - 4.14.2-4 - Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] - bugfix for XSA-380 - stop editing grub files in /boot/efi/EFI/fedora on Fedora 34 --------------------------------------------------------------------------------References: [ 1 ] Bug #2002785 - CVE-2021-28701 xen: another race in XENMAPSPACE_grant_table handling https://bugzilla.redhat.com/show_bug.cgi?id=2002785 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-11577e5229' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, privilege escalation or memory disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4888-1
Multiple vulnerabilities have been discovered in the Xen hypervisor: Several security issues affecting Xenstore could result in cross domain access (denial of service, information leaks or privilege . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4812-1
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, privilege escalation or information leaks. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4804-1
Get the latest Linux and open source security news straight to your inbox.