From 99b6e78ec62d3b37a160bd47c8df26ce33e32742 Mon Sep 17 00:00:00 2001 From: Hans van Kranenburg Date: Tue, 15 Dec 2020 11:25:55 +0100 Subject: [PATCH] debian/changelog: add a few missing CVE numbers Signed-off-by: Hans van Kranenburg --- debian/changelog | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/debian/changelog b/debian/changelog index 2f30af981b..bf8cc96f4b 100644 --- a/debian/changelog +++ b/debian/changelog @@ -21,15 +21,15 @@ xen (4.14.0+80-gd101b417b7-1~exp1) experimental; urgency=medium * Update to new upstream version 4.14.0+80-gd101b417b7, which also contains security fixes for the following issues: - Information leak via power sidechannel - XSA-351 (no CVE yet) + XSA-351 CVE-2020-28368 - x86 PV guest INVLPG-like flushes may leave stale TLB entries - XSA-286 (no CVE yet) + XSA-286 CVE-2020-27674 - unsafe AMD IOMMU page table updates - XSA-347 (no CVE yet) + XSA-347 CVE-2020-27670 - undue deferral of IOMMU TLB flushes - XSA-346 (no CVE yet) + XSA-346 CVE-2020-27671 - x86: Race condition in Xen mapping code - XSA-345 (no CVE yet) + XSA-345 CVE-2020-27672 - lack of preemption in evtchn_reset() / evtchn_destroy() XSA-344 CVE-2020-25601 - races with evtchn_reset() -- 2.30.2