[Git][security-tracker-team/security-tracker][master] xen DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Aug 9 20:33:21 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d338b1d3 by Moritz Mühlenhoff at 2026-08-09T21:32:19+02:00
xen DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -79291,7 +79291,6 @@ CVE-2026-6691 (The MongoDB C Driver's Cyrus SASL integration performs unsafe str
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/d9c26f49e75d3de746a690db9c81ff5b4f6e21b0 (2.2.0)
 CVE-2026-23556 (When oxenstored is tearing a domain down, the node data is cleaned up  ...)
 	- xen 4.20.3+127-gc42374a105-1
-	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-483.html
@@ -79305,7 +79304,6 @@ CVE-2026-31786 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://xenbits.xen.org/xsa/advisory-485.html
 CVE-2026-23558 (The adjustments made for XSA-379 as well as those subsequently becomin ...)
 	- xen 4.20.3+127-gc42374a105-1
-	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-486.html
@@ -85011,7 +85009,6 @@ CVE-2026-1559 (The Youzify plugin for WordPress is vulnerable to Stored Cross-Si
 	NOT-FOR-US: WordPress plugin
 CVE-2025-54505 (A transient execution vulnerability within AMD CPUs may allow a local  ...)
 	- xen 4.20.3+127-gc42374a105-1
-	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (not supported under bullseye)
 	NOTE: AMD CPU HW issue:
@@ -199345,14 +199342,12 @@ CVE-2024-9453 (A vulnerability was found in Red Hat OpenShift Jenkins. The beare
 	NOT-FOR-US: Red Hat OpenShift Jenkins
 CVE-2026-23555 (Any guest issuing a Xenstore command accessing a node using the (illeg ...)
 	- xen 4.20.3+127-gc42374a105-1 (unimportant)
-	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <not-affected> (Vulnerable code not present)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-481.html
 	NOTE: Debian uses the ocaml-based xenstored
 CVE-2026-23554 (The Intel EPT paging code uses an optimization to defer flushing of an ...)
 	- xen 4.20.3+127-gc42374a105-1
-	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <not-affected> (Vulnerable code not present)
 	NOTE: https://xenbits.xen.org/xsa/advisory-480.html


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[09 Aug 2026] DSA-6424-1 xen - security update
+	{CVE-2025-10263 CVE-2025-54505 CVE-2025-54518 CVE-2026-23554 CVE-2026-23555 CVE-2026-23556 CVE-2026-23557 CVE-2026-23558 CVE-2026-42487 CVE-2026-42488 CVE-2026-42489 CVE-2026-42490 CVE-2026-42493 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 CVE-2026-62426 CVE-2026-62427 CVE-2026-62428 CVE-2026-62429 CVE-2026-62430 CVE-2026-62431 CVE-2026-62432 CVE-2026-62433 CVE-2026-62434 CVE-2026-62435 CVE-2026-62436}
+	[trixie] - xen 4.20.3+127-gc42374a105-0+deb13u1
 [09 Aug 2026] DSA-6423-1 kitty - security update
 	{CVE-2026-42850 CVE-2026-42851 CVE-2026-54055 CVE-2026-54057}
 	[trixie] - kitty 0.41.1-2+deb13u2


=====================================
data/dsa-needed.txt
=====================================
@@ -156,8 +156,6 @@ vips
 wordpress (carnil)
   Maintainer prepared update, asked for review
 --
-xen (jmm)
---
 xorg-server
 --
 xrdp



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d338b1d30838226d2b5127515f4961245fde1613

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d338b1d30838226d2b5127515f4961245fde1613
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/77ca482c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list