stable

xen-4.15.3-7.fc35

FEDORA-2022-99af00f60e created by myoung 2 years ago for Fedora 35

Xenstore: Guests can crash xenstored [XSA-414, CVE-2022-42309] Xenstore: Guests can create orphaned Xenstore nodes [XSA-415, CVE-2022-42310] Xenstore: guests can let run xenstored out of memory [XSA-326, CVE-2022-42311, CVE-2022-42312, CVE-2022-42313, CVE-2022-42314, CVE-2022-42315, CVE-2022-42316, CVE-2022-42317, CVE-2022-42318] Xenstore: Guests can cause Xenstore to not free temporary memory [XSA-416, CVE-2022-42319] Xenstore: Guests can get access to Xenstore nodes of deleted domains [XSA-417, CVE-2022-42320] Xenstore: Guests can crash xenstored via exhausting the stack [XSA-418, CVE-2022-42321] Xenstore: Cooperating guests can create arbitrary numbers of nodes [XSA-419, CVE-2022-42322, CVE-2022-42323] Oxenstored 32->31 bit integer truncation issues [XSA-420, CVE-2022-42324] Xenstore: Guests can create arbitrary number of nodes via transactions [XSA-421, CVE-2022-42325, CVE-2022-42326]


add patch to fix an incorrect backport Arm: unbounded memory consumption for 2nd-level page tables [XSA-409, CVE-2022-33747] (#2135268) P2M pool freeing may take excessively long [XSA-410, CVE-2022-33746] (#2135641) lock order inversion in transitive grant copy handling [XSA-411, CVE-2022-33748] (#2135263)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2022-99af00f60e

This update has been submitted for testing by myoung.

2 years ago

This update's test gating status has been changed to 'waiting'.

2 years ago

This update has obsoleted xen-4.15.3-6.fc35, and has inherited its bugs and notes.

2 years ago

This update's test gating status has been changed to 'failed'.

2 years ago

This update's test gating status has been changed to 'passed'.

2 years ago

This update has been pushed to testing.

2 years ago

This update has been submitted for stable by bodhi.

2 years ago

This update has been submitted for stable by bodhi.

2 years ago

This update has been submitted for stable by bodhi.

2 years ago

This update has been pushed to stable.

2 years ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
2 years ago
in testing
2 years ago
in stable
2 years ago
BZ#2135262 CVE-2022-33748 xen: lock order inversion in transitive grant copy handling
0
0
BZ#2135263 CVE-2022-33748 xen: lock order inversion in transitive grant copy handling [fedora-all]
0
0
BZ#2135267 CVE-2022-33747 xen: unbounded memory consumption for 2nd-level page tables
0
0
BZ#2135268 CVE-2022-33747 xen: unbounded memory consumption for 2nd-level page tables [fedora-all]
0
0
BZ#2135640 CVE-2022-33746 xen: P2M pool freeing may take excessively long
0
0
BZ#2135641 CVE-2022-33746 xen: P2M pool freeing may take excessively long [fedora-all]
0
0

Automated Test Results