[Pkg-xen-devel] xen_4.20.3+127-gc42374a105-0+deb13u1_source.changes ACCEPTED into proposed-updates->stable-new
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Sun Aug 9 20:53:52 BST 2026
Thank you for your contribution to Debian.
Mapping stable-security to proposed-updates.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Jul 2026 23:59:26 +0200
Source: xen
Architecture: source
Version: 4.20.3+127-gc42374a105-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Xen Team <pkg-xen-devel at lists.alioth.debian.org>
Changed-By: Hans van Kranenburg <hans at knorrie.org>
Closes: 1129037
Changes:
xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=medium
.
* Update to new upstream version 4.20.3+127-gc42374a105, which also contains
security fixes for the following issues:
(Closes: #1129037)
- Use after free of paging structures in EPT
XSA-480 CVE-2026-23554
- Xenstored DoS by unprivileged domain
XSA-481 CVE-2026-23555
- oxenstored keeps quota related use counts across domain destruction
XSA-483 CVE-2026-23556
- Xenstored DoS via XS_RESET_WATCHES command
XSA-484 CVE-2026-23557
- grant table v2 race in status page mapping
XSA-486 CVE-2026-23558
- x86: Floating Point Divider State Sampling
XSA-488 CVE-2025-54505
- x86: CPU Opcode Cache corruption
XSA-490 CVE-2025-54518
- x86 HVM I/O port list traversal
XSA-491 CVE-2026-42487
- domctl lock open to abuse
XSA-492 CVE-2026-42489 CVE-2026-42490
- Arm: Completion of memory accesses not guaranteed by completion of a TLBI
XSA-493 CVE-2025-10263
- x86: mismatched mapcache metadata
XSA-494 CVE-2026-42488
- x86 shadow paging is deprecated
XSA-495 CVE-2026-42493
- buffer overruns in libfsimage iso9660 handling
XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425
- sysctl and platform-op locks open to abuse
XSA-499 CVE-2026-62426 CVE-2026-62427
- grant-table: type confusion in grant-copy
XSA-500 CVE-2026-62428
- grant-table: version change racing with other operations
XSA-501 CVE-2026-62435 CVE-2026-62436
- vNUMA domain cleanup may race other operations
XSA-502 CVE-2026-62429
- x86: Out-of-bounds read in vRTC emulation
XSA-503 CVE-2026-62430
- Viridian STIMER division by zero
XSA-504 CVE-2026-62431
- evtchn: Race between FIFO expand and reset
XSA-505 CVE-2026-62432
- correct buffer checks for DM_OP hypercalls
XSA-506 CVE-2026-62433
- PoD: Don't try to reclaim special pages
XSA-507 CVE-2026-62434
- pygrub: security-supported only when run de-privileged
XSA-508
* Drop the following patches which are now included upstream:
- ARM: Drop ThumbEE support
- xen/arm: Set ThumbEE as not present in PFR0
* Note that the following XSA are not listed, because...
- XSA-482 has patches for the Linux kernel
- XSA-485 has patches for the Linux kernel
- XSA-487 has patches for the Linux kernel
- XSA-489 applies to XAPI which is not included in Debian
- XSA-496 only applies to Xen 4.21 and later
- XSA-498 applies to XAPI which is not included in Debian
.
xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=medium
.
* Update to new upstream version 4.20.2+37-g61ff35323e, which also contains
security fixes for the following issues:
- x86: buffer overrun with shadow paging + tracing
XSA-477 CVE-2025-58150
- x86: incomplete IBPB for vCPU isolation
XSA-479 CVE-2026-23553
* Note that the following XSA are not listed, because...
- XSA-478 applies to XAPI which is not included in Debian
Checksums-Sha1:
dbefdd4e57cb83580029c043e5ed8abe21d8fd1c 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz
41425edd82e9c7c6760b46905cd75b928a693ad4 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
Checksums-Sha256:
659b0858c1559ed7203c09d2eeb6091e50735b78079158ec7e94de573528d6f7 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz
b1f909d626f3d4ba6965ba291dd97b0dfbbe48bb8e2510913cbc1760c5e8cb3e 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
Files:
ce25ea9a9a2d953006437dee63b6a04f 4061 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc42374a105.orig.tar.xz
c861bf1c0396b067c5b040d5fb164687 139540 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp3DGAACgkQEMKTtsN8
TjamrxAAwEQ5GT89wPUseyBqvX5nwlu2w41jzRHHJTpPb/y1kDagOyW5iFfZLWL/
FxEYjb7BzjLCNsUVVlfUi/H0NMeFzkWwMbik7obcUvxMULHVYl8LBUAK0h+MD5WS
yTPwy4kh3Mih8vfZ9YFIr9bBcOfB7wnz8ADfxsQRBqIZoyjKVcA3nVG3pjZeUKsR
bdwOD8FzHqK6UVYS97tRfJgMqWpAHLI/AshUIn+iy5g0FmSmt3JeJQsw2klFOCAd
589KObPF2nIGgeokFJ8Xotyk9JMXOxor6yzCuMMjjJAHSaq7qC6hvj/lXNkL8ErN
tKdScOZtDHyH5sXS39fAxH+oVv7p0BJvO1EfOiSeY47ckRc42KQmDNGVrOzCP+E8
yUCi58pwQaHT4AiQNhTD8AY4sGbAEMOCIwOarz3aVLKNXEz+zqh3CXY4NFO3waEI
TvEfH8K2j06KJNkg7vWcoRugZ574w7TdIVYuqHLvnFgR7dLZBiyaRL/0qyqWrkvl
NvnIqtuc8G6UwNt6DMXzqwVVBsy/tSdTJlwOhh2ew1F49DuLkDHYuFvudm38qmgH
zXCGbcRDtbly1k9U7ogLGm2zoeOVu5CXN9ONmkan+JrR3ozhQeWDh+CJlIIqkAwN
LAzSXpmpY5H2zxnmTvyuOxBegYVZBVLYxo7wj8+OblVVE//Y3KY=
=wGHr
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-xen-devel/attachments/20260809/13acd827/attachment.sig>
More information about the Pkg-xen-devel
mailing list