[Git][security-tracker-team/security-tracker][master] 2 commits: Track fixed xen issues in unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Jul 12 20:14:56 BST 2021
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b2cb63f1 by Salvatore Bonaccorso at 2021-07-12T21:13:58+02:00
Track fixed xen issues in unstable
- - - - -
2cd1fa5c by Salvatore Bonaccorso at 2021-07-12T21:14:25+02:00
Remove postponed bullseye entry fo CVE-2021-28687/xen
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18176,13 +18176,13 @@ CVE-2021-28695
CVE-2021-28694
RESERVED
CVE-2021-28693 (xen/arm: Boot modules are not scrubbed The bootloader will load boot m ...)
- - xen <unfixed>
+ - xen 4.14.2+25-gb6a8c4f72d-1
[buster] - xen <not-affected> (Only affects 4.12 and later)
[stretch] - xen <not-affected> (Only affects 4.12 and later)
NOTE: https://xenbits.xen.org/xsa/advisory-372.html
CVE-2021-28692 (inappropriate x86 IOMMU timeout detection / handling IOMMUs process co ...)
{DSA-4931-1}
- - xen <unfixed>
+ - xen 4.14.2+25-gb6a8c4f72d-1
[stretch] - xen <end-of-life> (DSA 4602-1)
NOTE: https://xenbits.xen.org/xsa/advisory-373.html
CVE-2021-28691 (Guest triggered use-after-free in Linux xen-netback A malicious or bug ...)
@@ -18192,7 +18192,7 @@ CVE-2021-28691 (Guest triggered use-after-free in Linux xen-netback A malicious
NOTE: https://xenbits.xen.org/xsa/advisory-374.html
CVE-2021-28690 (x86: TSX Async Abort protections not restored after S3 This issue rela ...)
{DSA-4931-1}
- - xen <unfixed>
+ - xen 4.14.2+25-gb6a8c4f72d-1
[stretch] - xen <end-of-life> (DSA 4602-1)
NOTE: https://xenbits.xen.org/xsa/advisory-377.html
CVE-2021-28689 (x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests ...)
@@ -18292,8 +18292,7 @@ CVE-2021-3449 (An OpenSSL TLS server may crash if sent a maliciously crafted ren
NOTE: Fixed by: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=fb9fa6b51defd48157eeb207f52181f735d96148 (OpenSSL_1_1_1k)
NOTE: Followup: https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=d33c2a3d8453a75509bcc8d2cf7d2dc2a3a518d0
CVE-2021-28687 (HVM soft-reset crashes toolstack libxl requires all data structures pa ...)
- - xen <unfixed>
- [bullseye] - xen <postponed> (Fix along with next round of updates)
+ - xen 4.14.2+25-gb6a8c4f72d-1
[buster] - xen <not-affected> (Vulnerable code introduced later)
[stretch] - xen <not-affected> (Vulnerable code introduced later)
NOTE: https://xenbits.xen.org/xsa/advisory-368.html
@@ -23878,7 +23877,7 @@ CVE-2021-26314 (Potential floating point value injection in all supported CPU pr
TODO: check
CVE-2021-26313 (Potential speculative code store bypass in all supported CPU products, ...)
{DSA-4931-1}
- - xen <unfixed>
+ - xen 4.14.2+25-gb6a8c4f72d-1
[stretch] - xen <end-of-life> (DSA 4602-1)
NOTE: https://xenbits.xen.org/xsa/advisory-375.html
NOTE: https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003
@@ -51270,7 +51269,7 @@ CVE-2021-0090 (Uncontrolled search path element in Intel(R) DSA before version 2
NOT-FOR-US: Intel
CVE-2021-0089 (Observable response discrepancy in some Intel(R) Processors may allow ...)
{DSA-4931-1}
- - xen <unfixed>
+ - xen 4.14.2+25-gb6a8c4f72d-1
[stretch] - xen <end-of-life> (DSA 4602-1)
NOTE: https://xenbits.xen.org/xsa/advisory-375.html
NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00516.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2673763353a97a065e37ccfbe251d13ba4350c0f...2cd1fa5c27b3ced116946de504b655d456922317
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2673763353a97a065e37ccfbe251d13ba4350c0f...2cd1fa5c27b3ced116946de504b655d456922317
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210712/823d4b2c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list