[From nobody Tue Jul 28 23:53:06 2026
Received: (at 1129037-close) by bugs.debian.org; 28 Jul 2026 22:49:16 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 357; hammy, 148; neutral, 236; spammy,
 2. spammytokens:1.000-7--38l, 1.000-7--38L
 hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo.
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:58952)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1woqbs-00BEQM-1X for 1129037-close@bugs.debian.org;
 Tue, 28 Jul 2026 22:49:16 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1woqbr-00B8Lh-2q for 1129037-close@bugs.debian.org;
 Tue, 28 Jul 2026 22:49:15 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=nOm/njx4D4PcaBv8VbDwys5equIa3yVnUQqpCq5G8yU=; b=rJ/QTaSg9njxJVi3UfhkSDhj2n
 1Y7TdREqq5u4hMDqHxJPp570F8mqHe+f91u4IPXHNbaA88++6vh1jzsJ2vSU8vGgCFWyd8blPN7qD
 8V2x3OyqGnNXWagP+ILSY9kvO89dgvyySE9p9/diR/arFPCBKU7lQV4ay3OKvVYI1DHjZ/cX6Nek1
 qv282/Yyl46wIGhatPBzNd6kPAS1UF6eAcSpCf7OhO36TRXBoA1Lxtsct71zNO8Oy2UKn4ZAKKBGw
 q2o5AcDjfyohfTLQYHYIaznccN8r+OOdyx+7L+0y4BbiGgO/7oKw5p2lRWtc1fnDiOSEEdVt5LSbe
 QZVo2oKg==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1woqbr-0000000GxFK-0KHa; Tue, 28 Jul 2026 22:49:15 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Hans van Kranenburg &lt;hans@knorrie.org&gt;
To: 1129037-close@bugs.debian.org
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: xen
Debian: DAK
Debian-Changes: xen_4.20.3+127-gc42374a105-1_source.changes
Debian-Source: xen
Debian-Version: 4.20.3+127-gc42374a105-1
Debian-Architecture: source
Debian-Suite: unstable
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1129037: fixed in xen 4.20.3+127-gc42374a105-1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============3552534636152747136==&quot;
Message-Id: &lt;E1woqbr-0000000GxFK-0KHa@fasolo.debian.org&gt;
Date: Tue, 28 Jul 2026 22:49:15 +0000

--===============3552534636152747136==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: xen
Source-Version: 4.20.3+127-gc42374a105-1
Done: Hans van Kranenburg &lt;hans@knorrie.org&gt;

We believe that the bug you reported is fixed in the latest version of
xen, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1129037@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Hans van Kranenburg &lt;hans@knorrie.org&gt; (supplier of updated xen package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 28 Jul 2026 20:42:50 +0200
Source: xen
Architecture: source
Version: 4.20.3+127-gc42374a105-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Xen Team &lt;pkg-xen-devel@lists.alioth.debian.org&gt;
Changed-By: Hans van Kranenburg &lt;hans@knorrie.org&gt;
Closes: 1129037
Changes:
 xen (4.20.3+127-gc42374a105-1) unstable; urgency=3Dmedium
 .
   * Update to new upstream version 4.20.3+127-gc42374a105, which also contai=
ns
     security fixes for the following issues:
     (Closes: #1129037)
     - Use after free of paging structures in EPT
       XSA-480 CVE-2026-23554
     - Xenstored DoS by unprivileged domain
       XSA-481 CVE-2026-23555
     - oxenstored keeps quota related use counts across domain destruction
       XSA-483 CVE-2026-23556
     - Xenstored DoS via XS_RESET_WATCHES command
       XSA-484 CVE-2026-23557
     - grant table v2 race in status page mapping
       XSA-486 CVE-2026-23558
     - x86: Floating Point Divider State Sampling
       XSA-488 CVE-2025-54505
     - x86: CPU Opcode Cache corruption
       XSA-490 CVE-2025-54518
     - x86 HVM I/O port list traversal
       XSA-491 CVE-2026-42487
     - domctl lock open to abuse
       XSA-492 CVE-2026-42489 CVE-2026-42490
     - Arm: Completion of memory accesses not guaranteed by completion of a T=
LBI
       XSA-493 CVE-2025-10263
     - x86: mismatched mapcache metadata
       XSA-494 CVE-2026-42488
     - x86 shadow paging is deprecated
       XSA-495 CVE-2026-42493
     - buffer overruns in libfsimage iso9660 handling
       XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CV=
E-2026-62425
     - sysctl and platform-op locks open to abuse
       XSA-499 CVE-2026-62426 CVE-2026-62427
     - grant-table: type confusion in grant-copy
       XSA-500 CVE-2026-62428
     - grant-table: version change racing with other operations
       XSA-501 CVE-2026-62435 CVE-2026-62436
     - vNUMA domain cleanup may race other operations
       XSA-502 CVE-2026-62429
     - x86: Out-of-bounds read in vRTC emulation
       XSA-503 CVE-2026-62430
     - Viridian STIMER division by zero
       XSA-504 CVE-2026-62431
     - evtchn: Race between FIFO expand and reset
       XSA-505 CVE-2026-62432
     - correct buffer checks for DM_OP hypercalls
       XSA-506 CVE-2026-62433
     - PoD: Don't try to reclaim special pages
       XSA-507 CVE-2026-62434
     - pygrub: security-supported only when run de-privileged
       XSA-508
   * Drop the following patches which are now included upstream:
     - ARM: Drop ThumbEE support
     - xen/arm: Set ThumbEE as not present in PFR0
   * Note that the following XSA are not listed, because...
     - XSA-482 has patches for the Linux kernel
     - XSA-485 has patches for the Linux kernel
     - XSA-487 has patches for the Linux kernel
     - XSA-489 applies to XAPI which is not included in Debian
     - XSA-496 only applies to Xen 4.21 and later
     - XSA-498 applies to XAPI which is not included in Debian
Checksums-Sha1:
 7eb0d2019ed088ce46154441d0396c8c2037c977 4154 xen_4.20.3+127-gc42374a105-1.d=
sc
 db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.=
orig.tar.xz
 a5c96e34735baae759dbe47eb26f2c420986441e 139540 xen_4.20.3+127-gc42374a105-1=
.debian.tar.xz
Checksums-Sha256:
 74299b01a9855f780d8e0b31d56a1bc27f776d73a1926456cac860f3adde48a2 4154 xen_4.=
20.3+127-gc42374a105-1.dsc
 df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen=
_4.20.3+127-gc42374a105.orig.tar.xz
 96d44c57b99010618402d0762e3579a58e32c544e3afbe4edb254edb5b96f653 139540 xen_=
4.20.3+127-gc42374a105-1.debian.tar.xz
Files:
 4b160e197677b6f97da856ca2758f017 4154 admin optional xen_4.20.3+127-gc42374a=
105-1.dsc
 9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc423=
74a105.orig.tar.xz
 b36c7b8aff830ffd648ffb3ee21172d7 139540 admin optional xen_4.20.3+127-gc4237=
4a105-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEESWyddwNaG9637koYssHfcmNhX2wFAmppK18ACgkQssHfcmNh
X2z+eA//Zx48n3To5xItLaNhrzG3V9wJ+s//wPCOFUHCUhdLVsFwQ8OQzszpTlUx
POmqQ33c+5gYSc0tOxCQNG1bGEROCnbdVLC2/HV0s3oAr/lR+MBv+kmqFir1jqo3
pqoGGBV11rZvAp8sXXjPlQMg0B1nSIDEBGKhXVqrgDIzQMeWcpvv5WZVhaqkRZxW
LsRVBj3MQe+Qfeo3hIjRoKXtE0LjPmLYDmhqDDVpn6LnYzxZ9jgeTmohk2eX2+Yy
uheY0S6CbliGIFdjVJJsR+Hx5hx9MNWXf7r7yrIQOrJ7k9mlACzC8+Ib6q02heyJ
9kunQ5hkUqEJz0FP2XmAxE9nxP8ygM0BYbZENlFHI3BzXRtQpqnMwH9mYYXKO4rW
l9iP96bU7TjyJiW4uW5dAZJRSF6h0lQLegH8G98HW9cJFlPcQ8Tru/XxsSwMs/Bh
hRCdRj5XL7Ol3olK07fuAaln/vtkgqhGtr+yw0hZzuFPa4u6K6etKS3dzDA9zk0U
u0ySShk0TOIsNbhmd1x/jH2UfSY3bhV5r1Q7ahoRPhQqcu5JYmK7BJgn6IjNZ7w9
38L+O2zRynSo5TevQzjR+Viskd5BlgtUguXU5aK+eFZ0u3XI6tJHed3Ka4od3pDQ
GX2AzFEOUz+Idc2mU2H0YxgLjT75xtWbM1FYL3Mny0NmMl6Y1f0=3D
=3D4J0B
-----END PGP SIGNATURE-----


--===============3552534636152747136==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCamkx6wAKCRCb9qggYcy5
IS4QAP44riyhJE+EdE9Mr0dloq4l7x7mxMbCJfjO29GMNvL2rAD/R7oXdkPdZMsQ
Yj/QViI5zuf/kGYjXF+kxaC86pt/hAI=
=u/RH
-----END PGP SIGNATURE-----

--===============3552534636152747136==--
]