xen (4.11.4+
107-gef32c7afa2-1) buster-security; urgency=high
* Update to new upstream version 4.11.4+
107-gef32c7afa2, which also contains
security fixes for the following issues:
- inappropriate x86 IOMMU timeout detection / handling
XSA-373 CVE-2021-28692
- Speculative Code Store Bypass
XSA-375 CVE-2021-0089 CVE-2021-26313
- x86: TSX Async Abort protections not restored after S3
XSA-377 CVE-2021-28690
* Note that the following XSA are not listed, because...
- XSA-370 does not contain code changes.
- XSA-371 and XSA-374 have patches for the Linux kernel.
- XSA-372 only applies to Xen 4.12 and newer.
[dgit import unpatched xen 4.11.4+
107-gef32c7afa2-1]