From cabcc55894eaeb6351c50c95fa8ce6eb111a368b Mon Sep 17 00:00:00 2001 From: Sam James Date: Mon, 12 Jul 2021 03:49:49 +0100 Subject: [ GLSA 202107-30 ] Xen: Multiple vulnerabilities Signed-off-by: Sam James --- glsa-202107-30.xml | 73 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 73 insertions(+) create mode 100644 glsa-202107-30.xml (limited to 'glsa-202107-30.xml') diff --git a/glsa-202107-30.xml b/glsa-202107-30.xml new file mode 100644 index 000000000000..bd790484fb22 --- /dev/null +++ b/glsa-202107-30.xml @@ -0,0 +1,73 @@ + + + + Xen: Multiple vulnerabilities + Multiple vulnerabilities have been found in Xen, the worst of which + could result in privilege escalation. + + xen + 2021-07-12 + 2021-07-12 + 760144 + 766474 + 783456 + 795054 + local, remote + + + 4.14.2-r1 + 4.15.0-r1 + 4.15.0-r1 + + + +

Xen is a bare-metal hypervisor.

+
+ +

Multiple vulnerabilities have been discovered in Xen. Please review the + CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Xen 4.14.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.14.2-r1" + + +

All Xen 4.15.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.15.0-r1" + +
+ + CVE-2020-29479 + CVE-2020-29486 + CVE-2020-29487 + CVE-2020-29566 + CVE-2020-29567 + CVE-2020-29568 + CVE-2020-29569 + CVE-2020-29570 + CVE-2020-29571 + CVE-2021-0089 + CVE-2021-26313 + CVE-2021-28687 + CVE-2021-28690 + CVE-2021-28691 + CVE-2021-28692 + CVE-2021-28693 + CVE-2021-3308 + + ajak + ajak +
-- cgit v1.2.3-65-gdbad