xen (4.14.5+86-g1c354767d5-1) bullseye-security; urgency=medium
authorHans van Kranenburg <hans@knorrie.org>
Fri, 4 Nov 2022 19:25:46 +0000 (19:25 +0000)
committerHans van Kranenburg <hans@knorrie.org>
Fri, 4 Nov 2022 19:25:46 +0000 (19:25 +0000)
commit124b374ba3d1c05fafa216005bf6575aae11d0ea
tree948f8f1266be8fa0a629941eeb384dc0c544a196
parentc0e6dee78a1ed0ec26dfccf4414b8a5664a61ffd
parent48cad62e14818c360d5b7aa8a1ceb2eb2253475a
xen (4.14.5+86-g1c354767d5-1) bullseye-security; urgency=medium

  * Update to new upstream version 4.14.5+86-g1c354767d5, which also contains
    security fixes for the following issues: (Closes: #1021668)
    - Xenstore: guests can let run xenstored out of memory
      XSA-326 CVE-2022-42311 CVE-2022-42312 CVE-2022-42313 CVE-2022-42314
      CVE-2022-42315 CVE-2022-42316 CVE-2022-42317 CVE-2022-42318
    - insufficient TLB flush for x86 PV guests in shadow mode
      XSA-408 CVE-2022-33745
    - Arm: unbounded memory consumption for 2nd-level page tables
      XSA-409 CVE-2022-33747
    - P2M pool freeing may take excessively long
      XSA-410 CVE-2022-33746
    - lock order inversion in transitive grant copy handling
      XSA-411 CVE-2022-33748
    - Xenstore: Guests can crash xenstored
      XSA-414 CVE-2022-42309
    - Xenstore: Guests can create orphaned Xenstore nodes
      XSA-415 CVE-2022-42310
    - Xenstore: Guests can cause Xenstore to not free temporary memory
      XSA-416 CVE-2022-42319
    - Xenstore: Guests can get access to Xenstore nodes of deleted domains
      XSA-417 CVE-2022-42320
    - Xenstore: Guests can crash xenstored via exhausting the stack
      XSA-418 CVE-2022-42321
    - Xenstore: Cooperating guests can create arbitrary numbers of nodes
      XSA-419 CVE-2022-42322 CVE-2022-42323
    - Oxenstored 32->31 bit integer truncation issues
      XSA-420 CVE-2022-42324
    - Xenstore: Guests can create arbitrary number of nodes via transactions
      XSA-421 CVE-2022-42325 CVE-2022-42326
  * The upstream Xen changes now also contain the first mentioned patch of
    XSA-403 ("Linux disk/nic frontends data leaks") for stable branch lines.
    For more information, please refer to the XSA-403 advisory text.
  * Note that the following XSA are not listed, because...
    - XSA-412 only applies to Xen 4.16 and newer
    - XSA-413 applies to XAPI which is not included in Debian
  * Correct a typo in the previous changelog entry.

[dgit import unpatched xen 4.14.5+86-g1c354767d5-1]
121 files changed:
debian/NEWS
debian/README.Debian.security
debian/README.md
debian/changelog
debian/compat
debian/control
debian/control.md5sum
debian/copyright
debian/gitignore-old
debian/installsharedlibs
debian/libxen-V.bug-control.vsn-in
debian/libxen-dev.install
debian/libxencall1.install
debian/libxendevicemodel1.install
debian/libxenevtchn1.install
debian/libxenforeignmemory1.install
debian/libxengnttab1.install
debian/libxenhypfs1.install
debian/libxenmiscV.install.vsn-in
debian/libxenmiscV.lintian-overrides.vsn-in
debian/libxenstore3.0.install
debian/libxenstore3.0.symbols
debian/libxentoolcore1.install
debian/libxentoollog1.install
debian/not-installed
debian/patches/0001-Delete-config.sub-and-config.guess.patch
debian/patches/0002-Delete-configure-output.patch
debian/patches/0003-version.patch
debian/patches/0005-Do-not-ship-COPYING-into-usr-include.patch
debian/patches/0008-Do-not-build-the-instruction-emulator.patch
debian/patches/0009-tools-libfsimage-prefix.diff.patch
debian/patches/0010-autoconf-Provide-libexec_libdir_suffix.patch
debian/patches/0011-.gitignore-Add-configure-output-which-we-always-dele.patch
debian/patches/0012-Revert-pvshim-make-PV-shim-build-selectable-from-con.patch
debian/patches/0013-tools-firmware-Makfile-Respect-caller-s-CONFIG_PV_SH.patch
debian/patches/0014-tools-firmware-Makefile-CONFIG_PV_SHIM-enable-only-o.patch
debian/patches/0015-shim-Provide-separate-install-shim-target.patch
debian/patches/0016-docs-man-xen-vbd-interface.7-Provide-properly-format.patch
debian/patches/0017-Fix-empty-fields-in-first-hypervisor-log-line.patch
debian/patches/0018-vif-common-disable-handle_iptable.patch
debian/patches/0019-sysconfig.xencommons.in-Strip-and-debianize.patch
debian/patches/0020-hotplug-common-Do-not-adjust-LD_LIBRARY_PATH.patch
debian/patches/0021-pygrub-Set-sys.path.patch
debian/patches/0022-pygrub-Specify-rpath-LIBEXEC_LIB-when-building-fsima.patch
debian/patches/0023-tools-xl-bash-completion-also-complete-xen.patch
debian/patches/0024-tools-don-t-build-ship-xenmon.patch
debian/patches/0025-tools-Partially-revert-Cross-compilation-fixes.patch
debian/patches/0026-t-h-L-vif-common.sh-fix-handle_iptable-return-value.patch
debian/patches/0027-xen-rpi4-implement-watchdog-based-reset.patch
debian/patches/0028-tools-python-Pass-linker-to-Python-build-process.patch
debian/patches/0029-xen-arm-acpi-Don-t-fail-if-SPCR-table-is-absent.patch
debian/patches/0030-xen-acpi-Rework-acpi_os_map_memory-and-acpi_os_unmap.patch
debian/patches/0031-xen-arm-acpi-The-fixmap-area-should-always-be-cleare.patch
debian/patches/0032-xen-arm-Check-if-the-platform-is-not-using-ACPI-befo.patch
debian/patches/0033-xen-arm-Introduce-fw_unreserved_regions-and-use-it.patch
debian/patches/0034-xen-arm-acpi-add-BAD_MADT_GICC_ENTRY-macro.patch
debian/patches/0035-xen-arm-traps-Don-t-panic-when-receiving-an-unknown-.patch
debian/patches/0036-fix-spelling-errors.patch
debian/patches/0037-xen-don-t-have-timestamp-inserted-in-config.gz.patch
debian/patches/0038-x86-EFI-don-t-insert-timestamp-when-SOURCE_DATE_EPOC.patch
debian/patches/0039-docs-use-predictable-ordering-in-generated-documenta.patch
debian/patches/0040-docs-set-date-to-SOURCE_DATE_EPOCH-if-available.patch
debian/patches/0041-x86-ACPI-fix-mapping-of-FACS.patch
debian/patches/0042-x86-DMI-fix-table-mapping-when-one-lives-above-1Mb.patch
debian/patches/0043-x86-ACPI-fix-S3-wakeup-vector-mapping.patch
debian/patches/0044-x86-ACPI-don-t-invalidate-S5-data-when-S3-wakeup-vec.patch
debian/patches/misc/tools-pygrub-remove-static-solaris-support
debian/patches/misc/toolstestsx86_emulator-pass--no-pie--fno.patch
debian/patches/prefix-abiname/config-prefix.diff
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/scripts/Makefile
debian/scripts/qemu-ifup
debian/scripts/xen
debian/scripts/xen-dir
debian/scripts/xen-init-list
debian/scripts/xen-init-name
debian/scripts/xen-toolstack
debian/scripts/xen-toolstack-wrapper
debian/scripts/xen-utils-wrapper
debian/scripts/xen-version
debian/shuffle-binaries
debian/shuffle-boot-files
debian/source/format
debian/template-subst
debian/tree/xen-hypervisor-common/etc/default/grub.d/xen.cfg
debian/ucf-remove-fixup
debian/xen-doc.doc-base
debian/xen-doc.install
debian/xen-doc.links
debian/xen-doc.lintian-overrides
debian/xen-hypervisor-V-F.bug-control.vsn-in
debian/xen-hypervisor-V-F.install.vsn-in
debian/xen-hypervisor-V-F.lintian-overrides.vsn-in
debian/xen-hypervisor-V-F.postinst.vsn-in
debian/xen-hypervisor-V-F.postrm.vsn-in
debian/xen-hypervisor-common.docs
debian/xen-hypervisor-common.install
debian/xen-kconfig
debian/xen-utils-V.README.Debian.vsn-in
debian/xen-utils-V.bug-control.vsn-in
debian/xen-utils-V.install.vsn-in
debian/xen-utils-V.lintian-overrides.vsn-in
debian/xen-utils-V.postinst.vsn-in
debian/xen-utils-V.prerm.vsn-in
debian/xen-utils-common.README.Debian
debian/xen-utils-common.dirs
debian/xen-utils-common.examples
debian/xen-utils-common.install
debian/xen-utils-common.links
debian/xen-utils-common.maintscript
debian/xen-utils-common.postinst
debian/xen-utils-common.postrm
debian/xen-utils-common.preinst
debian/xen-utils-common.ucf
debian/xen-utils-common.xen.init
debian/xen-utils-common.xendomains.default
debian/xen-utils-common.xendomains.init
debian/xenstore-utils.install
debian/xenstore-utils.lintian-overrides