[Git][security-tracker-team/security-tracker][master] xen DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Aug 9 20:33:21 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d338b1d3 by Moritz Mühlenhoff at 2026-08-09T21:32:19+02:00
xen DSA
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -79291,7 +79291,6 @@ CVE-2026-6691 (The MongoDB C Driver's Cyrus SASL integration performs unsafe str
NOTE: https://github.com/mongodb/mongo-c-driver/commit/d9c26f49e75d3de746a690db9c81ff5b4f6e21b0 (2.2.0)
CVE-2026-23556 (When oxenstored is tearing a domain down, the node data is cleaned up ...)
- xen 4.20.3+127-gc42374a105-1
- [trixie] - xen <no-dsa> (Minor issue)
[bookworm] - xen <no-dsa> (Minor issue)
[bullseye] - xen <end-of-life> (EOLed in Bullseye)
NOTE: https://xenbits.xen.org/xsa/advisory-483.html
@@ -79305,7 +79304,6 @@ CVE-2026-31786 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://xenbits.xen.org/xsa/advisory-485.html
CVE-2026-23558 (The adjustments made for XSA-379 as well as those subsequently becomin ...)
- xen 4.20.3+127-gc42374a105-1
- [trixie] - xen <no-dsa> (Minor issue)
[bookworm] - xen <no-dsa> (Minor issue)
[bullseye] - xen <end-of-life> (EOLed in Bullseye)
NOTE: https://xenbits.xen.org/xsa/advisory-486.html
@@ -85011,7 +85009,6 @@ CVE-2026-1559 (The Youzify plugin for WordPress is vulnerable to Stored Cross-Si
NOT-FOR-US: WordPress plugin
CVE-2025-54505 (A transient execution vulnerability within AMD CPUs may allow a local ...)
- xen 4.20.3+127-gc42374a105-1
- [trixie] - xen <no-dsa> (Minor issue)
[bookworm] - xen <no-dsa> (Minor issue)
[bullseye] - xen <end-of-life> (not supported under bullseye)
NOTE: AMD CPU HW issue:
@@ -199345,14 +199342,12 @@ CVE-2024-9453 (A vulnerability was found in Red Hat OpenShift Jenkins. The beare
NOT-FOR-US: Red Hat OpenShift Jenkins
CVE-2026-23555 (Any guest issuing a Xenstore command accessing a node using the (illeg ...)
- xen 4.20.3+127-gc42374a105-1 (unimportant)
- [trixie] - xen <no-dsa> (Minor issue)
[bookworm] - xen <not-affected> (Vulnerable code not present)
[bullseye] - xen <end-of-life> (EOLed in Bullseye)
NOTE: https://xenbits.xen.org/xsa/advisory-481.html
NOTE: Debian uses the ocaml-based xenstored
CVE-2026-23554 (The Intel EPT paging code uses an optimization to defer flushing of an ...)
- xen 4.20.3+127-gc42374a105-1
- [trixie] - xen <no-dsa> (Minor issue)
[bookworm] - xen <no-dsa> (Minor issue)
[bullseye] - xen <not-affected> (Vulnerable code not present)
NOTE: https://xenbits.xen.org/xsa/advisory-480.html
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[09 Aug 2026] DSA-6424-1 xen - security update
+ {CVE-2025-10263 CVE-2025-54505 CVE-2025-54518 CVE-2026-23554 CVE-2026-23555 CVE-2026-23556 CVE-2026-23557 CVE-2026-23558 CVE-2026-42487 CVE-2026-42488 CVE-2026-42489 CVE-2026-42490 CVE-2026-42493 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 CVE-2026-62426 CVE-2026-62427 CVE-2026-62428 CVE-2026-62429 CVE-2026-62430 CVE-2026-62431 CVE-2026-62432 CVE-2026-62433 CVE-2026-62434 CVE-2026-62435 CVE-2026-62436}
+ [trixie] - xen 4.20.3+127-gc42374a105-0+deb13u1
[09 Aug 2026] DSA-6423-1 kitty - security update
{CVE-2026-42850 CVE-2026-42851 CVE-2026-54055 CVE-2026-54057}
[trixie] - kitty 0.41.1-2+deb13u2
=====================================
data/dsa-needed.txt
=====================================
@@ -156,8 +156,6 @@ vips
wordpress (carnil)
Maintainer prepared update, asked for review
--
-xen (jmm)
---
xorg-server
--
xrdp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d338b1d30838226d2b5127515f4961245fde1613
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d338b1d30838226d2b5127515f4961245fde1613
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/77ca482c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list