[Git][security-tracker-team/security-tracker][master] Track fixed version for xen issues addressed via unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 05:36:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0f476fdb by Salvatore Bonaccorso at 2026-07-29T06:35:37+02:00
Track fixed version for xen issues addressed via unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -40322,67 +40322,67 @@ CVE-2026-45447 (Issue summary: A specially crafted PKCS#7 or S/MIME signed messa
 	NOTE: Fixed by: https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54 (openssl-3.0.21)
 	NOTE: Fixed by: https://github.com/openssl/openssl/commit/18de9aba8294b5fb0915866cf3a1bb45f9599b8d (openssl-3.0.21)
 CVE-2026-62434 (A guest started with Populated on Demand enabled (PoD) can attempt to  ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-507.html
 CVE-2026-62433 (Parts of the DM_OP handling code assumes the caller has provided the r ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-506.html
 CVE-2026-62432 (The EVTCHNOP_expand_array hypercall checks for whether FIFO event chan ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-505.html
 CVE-2026-62431 (The logic to handle periodic Viridian STIMERs performs a division with ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-504.html
 CVE-2026-62430 (Accesses to the CMOS memory contents are done using an indirect IO por ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-503.html
 CVE-2026-62429 (Accessing the vNUMA configuration data of a guest is still possible wh ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-502.html
 CVE-2026-62435 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-501.html
 CVE-2026-62436 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-501.html
 CVE-2026-62428 (When grant-copy operations are processed, the respective grant may or  ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-500.html
 CVE-2026-62426 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-499.html
 CVE-2026-62427 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-499.html
 CVE-2026-42494 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-42495 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62423 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62424 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-62425 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-497.html
 CVE-2026-42492 (Xenstore, to have an up-to-date picture of the entire system, wants to ...)
@@ -40390,31 +40390,31 @@ CVE-2026-42492 (Xenstore, to have an up-to-date picture of the entire system, wa
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-496.html
 CVE-2026-42493 (Addressing certain issues, in particular related to operations which m ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-495.html
 CVE-2026-42488 (Some shadow paging errors paths will switch the page-tables without up ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-494.html
 CVE-2025-10263 (Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1 ...)
 	{DLA-4671-1 DLA-4665-1 DLA-4664-1}
 	- linux 7.0.13-1
 	[trixie] - linux 6.12.94-1
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-493.html
 	NOTE: Mitigations in src:linux: https://lore.kernel.org/all/20260609101203.1512409-1-mark.rutland@arm.com/
 CVE-2026-42490 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-492.html
 CVE-2026-42489 ([This CNA information record relates to multiple CVEs; the text explai ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-492.html
 CVE-2026-42487 (HVM guest I/O port accesses are subject to either emulation or at leas ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (out of LTS support)
 	NOTE: https://xenbits.xen.org/xsa/advisory-491.html
 CVE-2026-52907 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
@@ -60038,7 +60038,7 @@ CVE-2025-12659 (Siemens Simcenter Femapcontains a memory corruption vulnerabilit
 CVE-2024-54017 (A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All v ...)
 	NOT-FOR-US: Siemens
 CVE-2025-54518 (Improper isolation of shared resources within the CPU operation cache  ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-490.html
 	NOTE: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
@@ -69989,13 +69989,13 @@ CVE-2026-6691 (The MongoDB C Driver's Cyrus SASL integration performs unsafe str
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/b4984965877d559862e225beba09cb4e9d4a56a6 (2.2.0)
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/d9c26f49e75d3de746a690db9c81ff5b4f6e21b0 (2.2.0)
 CVE-2026-23556 (When oxenstored is tearing a domain down, the node data is cleaned up  ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-483.html
 CVE-2026-23557 (Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES c ...)
-	- xen <unfixed> (unimportant)
+	- xen 4.20.3+127-gc42374a105-1 (unimportant)
 	NOTE: https://xenbits.xen.org/xsa/advisory-484.html
 	NOTE: Debian uses the ocaml-based xenstored
 CVE-2026-31786 (In the Linux kernel, the following vulnerability has been resolved:  B ...)
@@ -70003,7 +70003,7 @@ CVE-2026-31786 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.0.3-1
 	NOTE: https://xenbits.xen.org/xsa/advisory-485.html
 CVE-2026-23558 (The adjustments made for XSA-379 as well as those subsequently becomin ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
@@ -75694,7 +75694,7 @@ CVE-2026-1838 (The Hostel plugin for WordPress is vulnerable to Reflected Cross-
 CVE-2026-1559 (The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Sc ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-54505 (A transient execution vulnerability within AMD CPUs may allow a local  ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <end-of-life> (not supported under bullseye)
@@ -189994,14 +189994,14 @@ CVE-2025-23970 (Incorrect Privilege Assignment vulnerability in aonetheme Servic
 CVE-2024-9453 (A vulnerability was found in Red Hat OpenShift Jenkins. The bearer tok ...)
 	NOT-FOR-US: Red Hat OpenShift Jenkins
 CVE-2026-23555 (Any guest issuing a Xenstore command accessing a node using the (illeg ...)
-	- xen <unfixed> (unimportant)
+	- xen 4.20.3+127-gc42374a105-1 (unimportant)
 	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <not-affected> (Vulnerable code not present)
 	[bullseye] - xen <end-of-life> (EOLed in Bullseye)
 	NOTE: https://xenbits.xen.org/xsa/advisory-481.html
 	NOTE: Debian uses the ocaml-based xenstored
 CVE-2026-23554 (The Intel EPT paging code uses an optimization to defer flushing of an ...)
-	- xen <unfixed>
+	- xen 4.20.3+127-gc42374a105-1
 	[trixie] - xen <no-dsa> (Minor issue)
 	[bookworm] - xen <no-dsa> (Minor issue)
 	[bullseye] - xen <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f476fdbd49c42d0c4d4df183a43db92407d6072

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0f476fdbd49c42d0c4d4df183a43db92407d6072
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/173fc1cb/attachment.htm>


More information about the debian-security-tracker-commits mailing list