[Pkg-xen-devel] xen_4.20.3+127-gc42374a105-0+deb13u1_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Sun Aug 9 20:53:52 BST 2026


Thank you for your contribution to Debian.

Mapping stable-security to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2026 23:59:26 +0200
Source: xen
Architecture: source
Version: 4.20.3+127-gc42374a105-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Xen Team <pkg-xen-devel at lists.alioth.debian.org>
Changed-By: Hans van Kranenburg <hans at knorrie.org>
Closes: 1129037
Changes:
 xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=medium
 .
   * Update to new upstream version 4.20.3+127-gc42374a105, which also contains
     security fixes for the following issues:
     (Closes: #1129037)
     - Use after free of paging structures in EPT
       XSA-480 CVE-2026-23554
     - Xenstored DoS by unprivileged domain
       XSA-481 CVE-2026-23555
     - oxenstored keeps quota related use counts across domain destruction
       XSA-483 CVE-2026-23556
     - Xenstored DoS via XS_RESET_WATCHES command
       XSA-484 CVE-2026-23557
     - grant table v2 race in status page mapping
       XSA-486 CVE-2026-23558
     - x86: Floating Point Divider State Sampling
       XSA-488 CVE-2025-54505
     - x86: CPU Opcode Cache corruption
       XSA-490 CVE-2025-54518
     - x86 HVM I/O port list traversal
       XSA-491 CVE-2026-42487
     - domctl lock open to abuse
       XSA-492 CVE-2026-42489 CVE-2026-42490
     - Arm: Completion of memory accesses not guaranteed by completion of a TLBI
       XSA-493 CVE-2025-10263
     - x86: mismatched mapcache metadata
       XSA-494 CVE-2026-42488
     - x86 shadow paging is deprecated
       XSA-495 CVE-2026-42493
     - buffer overruns in libfsimage iso9660 handling
       XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425
     - sysctl and platform-op locks open to abuse
       XSA-499 CVE-2026-62426 CVE-2026-62427
     - grant-table: type confusion in grant-copy
       XSA-500 CVE-2026-62428
     - grant-table: version change racing with other operations
       XSA-501 CVE-2026-62435 CVE-2026-62436
     - vNUMA domain cleanup may race other operations
       XSA-502 CVE-2026-62429
     - x86: Out-of-bounds read in vRTC emulation
       XSA-503 CVE-2026-62430
     - Viridian STIMER division by zero
       XSA-504 CVE-2026-62431
     - evtchn: Race between FIFO expand and reset
       XSA-505 CVE-2026-62432
     - correct buffer checks for DM_OP hypercalls
       XSA-506 CVE-2026-62433
     - PoD: Don't try to reclaim special pages
       XSA-507 CVE-2026-62434
     - pygrub: security-supported only when run de-privileged
       XSA-508
   * Drop the following patches which are now included upstream:
     - ARM: Drop ThumbEE support
     - xen/arm: Set ThumbEE as not present in PFR0
   * Note that the following XSA are not listed, because...
     - XSA-482 has patches for the Linux kernel
     - XSA-485 has patches for the Linux kernel
     - XSA-487 has patches for the Linux kernel
     - XSA-489 applies to XAPI which is not included in Debian
     - XSA-496 only applies to Xen 4.21 and later
     - XSA-498 applies to XAPI which is not included in Debian
 .
 xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=medium
 .
   * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains
     security fixes for the following issues:
     - x86: buffer overrun with shadow paging + tracing
       XSA-477 CVE-2025-58150
     - x86: incomplete IBPB for vCPU isolation
       XSA-479 CVE-2026-23553
   * Note that the following XSA are not listed, because...
     - XSA-478 applies to XAPI which is not included in Debian
Checksums-Sha1:
 dbefdd4e57cb83580029c043e5ed8abe21d8fd1c 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
 db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz
 41425edd82e9c7c6760b46905cd75b928a693ad4 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
Checksums-Sha256:
 659b0858c1559ed7203c09d2eeb6091e50735b78079158ec7e94de573528d6f7 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
 df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz
 b1f909d626f3d4ba6965ba291dd97b0dfbbe48bb8e2510913cbc1760c5e8cb3e 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz
Files:
 ce25ea9a9a2d953006437dee63b6a04f 4061 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.dsc
 9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc42374a105.orig.tar.xz
 c861bf1c0396b067c5b040d5fb164687 139540 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp3DGAACgkQEMKTtsN8
TjamrxAAwEQ5GT89wPUseyBqvX5nwlu2w41jzRHHJTpPb/y1kDagOyW5iFfZLWL/
FxEYjb7BzjLCNsUVVlfUi/H0NMeFzkWwMbik7obcUvxMULHVYl8LBUAK0h+MD5WS
yTPwy4kh3Mih8vfZ9YFIr9bBcOfB7wnz8ADfxsQRBqIZoyjKVcA3nVG3pjZeUKsR
bdwOD8FzHqK6UVYS97tRfJgMqWpAHLI/AshUIn+iy5g0FmSmt3JeJQsw2klFOCAd
589KObPF2nIGgeokFJ8Xotyk9JMXOxor6yzCuMMjjJAHSaq7qC6hvj/lXNkL8ErN
tKdScOZtDHyH5sXS39fAxH+oVv7p0BJvO1EfOiSeY47ckRc42KQmDNGVrOzCP+E8
yUCi58pwQaHT4AiQNhTD8AY4sGbAEMOCIwOarz3aVLKNXEz+zqh3CXY4NFO3waEI
TvEfH8K2j06KJNkg7vWcoRugZ574w7TdIVYuqHLvnFgR7dLZBiyaRL/0qyqWrkvl
NvnIqtuc8G6UwNt6DMXzqwVVBsy/tSdTJlwOhh2ew1F49DuLkDHYuFvudm38qmgH
zXCGbcRDtbly1k9U7ogLGm2zoeOVu5CXN9ONmkan+JrR3ozhQeWDh+CJlIIqkAwN
LAzSXpmpY5H2zxnmTvyuOxBegYVZBVLYxo7wj8+OblVVE//Y3KY=
=wGHr
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-xen-devel/attachments/20260809/13acd827/attachment.sig>


More information about the Pkg-xen-devel mailing list