[From nobody Wed Aug 12 06:23:06 2026
Received: (at 1129037-close) by bugs.debian.org; 12 Aug 2026 05:21:09 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 67; hammy, 150; neutral, 563; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:60716)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wu1On-00DB5U-0p for 1129037-close@bugs.debian.org;
 Wed, 12 Aug 2026 05:21:09 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wu1On-005cd9-0U for 1129037-close@bugs.debian.org;
 Wed, 12 Aug 2026 05:21:07 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=/JuBRAvwUfRZ/2PyWbHHoqjE2cyQ9SZgz7K9rBywre0=; b=hXZNVSGhlYZqaktMOQi1Kg053+
 zTF4ZsfqV1NlERSITIBi+3xhj2DrmC4CvPzCSmOUN+Mu+xmBzoKaCxHndVk66pdTQfJKo578Y+OxV
 BX0tON/B5O2blYjoG0XHGIgOhdJgb9b14gVcPa5ygAmVt6NoK1EY7KaBZsNHhJZGnGT3nrB0BCYei
 KCq15/LBZEoSo23xKpIp7/+vdQyZA51U5Wwtk9cRLJwn0ItbtaVlCOoFM7RrMI4jHYKtYJdz1Vy0C
 2rr5pNKzzvmgqYke64Y8Ca7UZWeDeXpdF90OLcoAC5JM+xzRz81UJAMPSC7EKn+kOCMtBNernMMdB
 mL/gH1fw==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1wu1Ok-00000009FmH-3wbV; Wed, 12 Aug 2026 05:21:06 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Hans van Kranenburg &lt;hans@knorrie.org&gt;
To: 1129037-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: xen
Debian: DAK
Debian-Changes: xen_4.20.3+127-gc42374a105-0+deb13u1_source.changes
Debian-Source: xen
Debian-Version: 4.20.3+127-gc42374a105-0+deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1129037: fixed in xen 4.20.3+127-gc42374a105-0+deb13u1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============3916883530207020311==&quot;
Message-Id: &lt;E1wu1Ok-00000009FmH-3wbV@fasolo.debian.org&gt;
Date: Wed, 12 Aug 2026 05:21:06 +0000

--===============3916883530207020311==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: xen
Source-Version: 4.20.3+127-gc42374a105-0+deb13u1
Done: Hans van Kranenburg &lt;hans@knorrie.org&gt;

We believe that the bug you reported is fixed in the latest version of
xen, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1129037@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Hans van Kranenburg &lt;hans@knorrie.org&gt; (supplier of updated xen package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2026 23:59:26 +0200
Source: xen
Architecture: source
Version: 4.20.3+127-gc42374a105-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Xen Team &lt;pkg-xen-devel@lists.alioth.debian.org&gt;
Changed-By: Hans van Kranenburg &lt;hans@knorrie.org&gt;
Closes: 1129037
Changes:
 xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=3Dmedium
 .
   * Update to new upstream version 4.20.3+127-gc42374a105, which also contai=
ns
     security fixes for the following issues:
     (Closes: #1129037)
     - Use after free of paging structures in EPT
       XSA-480 CVE-2026-23554
     - Xenstored DoS by unprivileged domain
       XSA-481 CVE-2026-23555
     - oxenstored keeps quota related use counts across domain destruction
       XSA-483 CVE-2026-23556
     - Xenstored DoS via XS_RESET_WATCHES command
       XSA-484 CVE-2026-23557
     - grant table v2 race in status page mapping
       XSA-486 CVE-2026-23558
     - x86: Floating Point Divider State Sampling
       XSA-488 CVE-2025-54505
     - x86: CPU Opcode Cache corruption
       XSA-490 CVE-2025-54518
     - x86 HVM I/O port list traversal
       XSA-491 CVE-2026-42487
     - domctl lock open to abuse
       XSA-492 CVE-2026-42489 CVE-2026-42490
     - Arm: Completion of memory accesses not guaranteed by completion of a T=
LBI
       XSA-493 CVE-2025-10263
     - x86: mismatched mapcache metadata
       XSA-494 CVE-2026-42488
     - x86 shadow paging is deprecated
       XSA-495 CVE-2026-42493
     - buffer overruns in libfsimage iso9660 handling
       XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CV=
E-2026-62425
     - sysctl and platform-op locks open to abuse
       XSA-499 CVE-2026-62426 CVE-2026-62427
     - grant-table: type confusion in grant-copy
       XSA-500 CVE-2026-62428
     - grant-table: version change racing with other operations
       XSA-501 CVE-2026-62435 CVE-2026-62436
     - vNUMA domain cleanup may race other operations
       XSA-502 CVE-2026-62429
     - x86: Out-of-bounds read in vRTC emulation
       XSA-503 CVE-2026-62430
     - Viridian STIMER division by zero
       XSA-504 CVE-2026-62431
     - evtchn: Race between FIFO expand and reset
       XSA-505 CVE-2026-62432
     - correct buffer checks for DM_OP hypercalls
       XSA-506 CVE-2026-62433
     - PoD: Don't try to reclaim special pages
       XSA-507 CVE-2026-62434
     - pygrub: security-supported only when run de-privileged
       XSA-508
   * Drop the following patches which are now included upstream:
     - ARM: Drop ThumbEE support
     - xen/arm: Set ThumbEE as not present in PFR0
   * Note that the following XSA are not listed, because...
     - XSA-482 has patches for the Linux kernel
     - XSA-485 has patches for the Linux kernel
     - XSA-487 has patches for the Linux kernel
     - XSA-489 applies to XAPI which is not included in Debian
     - XSA-496 only applies to Xen 4.21 and later
     - XSA-498 applies to XAPI which is not included in Debian
 .
 xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=3Dmedium
 .
   * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains
     security fixes for the following issues:
     - x86: buffer overrun with shadow paging + tracing
       XSA-477 CVE-2025-58150
     - x86: incomplete IBPB for vCPU isolation
       XSA-479 CVE-2026-23553
   * Note that the following XSA are not listed, because...
     - XSA-478 applies to XAPI which is not included in Debian
Checksums-Sha1:
 dbefdd4e57cb83580029c043e5ed8abe21d8fd1c 4061 xen_4.20.3+127-gc42374a105-0+d=
eb13u1.dsc
 db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.=
orig.tar.xz
 41425edd82e9c7c6760b46905cd75b928a693ad4 139540 xen_4.20.3+127-gc42374a105-0=
+deb13u1.debian.tar.xz
Checksums-Sha256:
 659b0858c1559ed7203c09d2eeb6091e50735b78079158ec7e94de573528d6f7 4061 xen_4.=
20.3+127-gc42374a105-0+deb13u1.dsc
 df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen=
_4.20.3+127-gc42374a105.orig.tar.xz
 b1f909d626f3d4ba6965ba291dd97b0dfbbe48bb8e2510913cbc1760c5e8cb3e 139540 xen_=
4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
Files:
 ce25ea9a9a2d953006437dee63b6a04f 4061 admin optional xen_4.20.3+127-gc42374a=
105-0+deb13u1.dsc
 9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc423=
74a105.orig.tar.xz
 c861bf1c0396b067c5b040d5fb164687 139540 admin optional xen_4.20.3+127-gc4237=
4a105-0+deb13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp3DGAACgkQEMKTtsN8
TjamrxAAwEQ5GT89wPUseyBqvX5nwlu2w41jzRHHJTpPb/y1kDagOyW5iFfZLWL/
FxEYjb7BzjLCNsUVVlfUi/H0NMeFzkWwMbik7obcUvxMULHVYl8LBUAK0h+MD5WS
yTPwy4kh3Mih8vfZ9YFIr9bBcOfB7wnz8ADfxsQRBqIZoyjKVcA3nVG3pjZeUKsR
bdwOD8FzHqK6UVYS97tRfJgMqWpAHLI/AshUIn+iy5g0FmSmt3JeJQsw2klFOCAd
589KObPF2nIGgeokFJ8Xotyk9JMXOxor6yzCuMMjjJAHSaq7qC6hvj/lXNkL8ErN
tKdScOZtDHyH5sXS39fAxH+oVv7p0BJvO1EfOiSeY47ckRc42KQmDNGVrOzCP+E8
yUCi58pwQaHT4AiQNhTD8AY4sGbAEMOCIwOarz3aVLKNXEz+zqh3CXY4NFO3waEI
TvEfH8K2j06KJNkg7vWcoRugZ574w7TdIVYuqHLvnFgR7dLZBiyaRL/0qyqWrkvl
NvnIqtuc8G6UwNt6DMXzqwVVBsy/tSdTJlwOhh2ew1F49DuLkDHYuFvudm38qmgH
zXCGbcRDtbly1k9U7ogLGm2zoeOVu5CXN9ONmkan+JrR3ozhQeWDh+CJlIIqkAwN
LAzSXpmpY5H2zxnmTvyuOxBegYVZBVLYxo7wj8+OblVVE//Y3KY=3D
=3DwGHr
-----END PGP SIGNATURE-----


--===============3916883530207020311==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanwCwgAKCRCb9qggYcy5
IR2SAP99wQk6LM4Pd+9LXf2o7t/+v9CpTq84SGBekHLr+kbPyQEAx3Hoim5TBp2O
1AMRjajuzt9ZYM6A6VVhMJgIyl3VWA4=
=Vc6m
-----END PGP SIGNATURE-----

--===============3916883530207020311==--
]