Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b2cb63f1 by Salvatore Bonaccorso at 2021-07-12T21:13:58+02:00
Track fixed xen issues in unstable

- - - - -
2cd1fa5c by Salvatore Bonaccorso at 2021-07-12T21:14:25+02:00
Remove postponed bullseye entry fo CVE-2021-28687/xen

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18176,13 +18176,13 @@ CVE-2021-28695
 CVE-2021-28694
        RESERVED
 CVE-2021-28693 (xen/arm: Boot modules are not scrubbed The bootloader will 
load boot m ...)
-       - xen <unfixed>
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [buster] - xen <not-affected> (Only affects 4.12 and later)
        [stretch] - xen <not-affected> (Only affects 4.12 and later)
        NOTE: https://xenbits.xen.org/xsa/advisory-372.html
 CVE-2021-28692 (inappropriate x86 IOMMU timeout detection / handling IOMMUs 
process co ...)
        {DSA-4931-1}
-       - xen <unfixed>
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [stretch] - xen <end-of-life> (DSA 4602-1)
        NOTE: https://xenbits.xen.org/xsa/advisory-373.html
 CVE-2021-28691 (Guest triggered use-after-free in Linux xen-netback A 
malicious or bug ...)
@@ -18192,7 +18192,7 @@ CVE-2021-28691 (Guest triggered use-after-free in Linux 
xen-netback A malicious
        NOTE: https://xenbits.xen.org/xsa/advisory-374.html
 CVE-2021-28690 (x86: TSX Async Abort protections not restored after S3 This 
issue rela ...)
        {DSA-4931-1}
-       - xen <unfixed>
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [stretch] - xen <end-of-life> (DSA 4602-1)
        NOTE: https://xenbits.xen.org/xsa/advisory-377.html
 CVE-2021-28689 (x86: Speculative vulnerabilities with bare (non-shim) 32-bit 
PV guests ...)
@@ -18292,8 +18292,7 @@ CVE-2021-3449 (An OpenSSL TLS server may crash if sent 
a maliciously crafted ren
        NOTE: Fixed by: 
https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=fb9fa6b51defd48157eeb207f52181f735d96148
 (OpenSSL_1_1_1k)
        NOTE: Followup: 
https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=d33c2a3d8453a75509bcc8d2cf7d2dc2a3a518d0
 CVE-2021-28687 (HVM soft-reset crashes toolstack libxl requires all data 
structures pa ...)
-       - xen <unfixed>
-       [bullseye] - xen <postponed> (Fix along with next round of updates)
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [buster] - xen <not-affected> (Vulnerable code introduced later)
        [stretch] - xen <not-affected> (Vulnerable code introduced later)
        NOTE: https://xenbits.xen.org/xsa/advisory-368.html
@@ -23878,7 +23877,7 @@ CVE-2021-26314 (Potential floating point value 
injection in all supported CPU pr
        TODO: check
 CVE-2021-26313 (Potential speculative code store bypass in all supported CPU 
products, ...)
        {DSA-4931-1}
-       - xen <unfixed>
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [stretch] - xen <end-of-life> (DSA 4602-1)
        NOTE: https://xenbits.xen.org/xsa/advisory-375.html
        NOTE: 
https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003
@@ -51270,7 +51269,7 @@ CVE-2021-0090 (Uncontrolled search path element in 
Intel(R) DSA before version 2
        NOT-FOR-US: Intel
 CVE-2021-0089 (Observable response discrepancy in some Intel(R) Processors may 
allow  ...)
        {DSA-4931-1}
-       - xen <unfixed>
+       - xen 4.14.2+25-gb6a8c4f72d-1
        [stretch] - xen <end-of-life> (DSA 4602-1)
        NOTE: https://xenbits.xen.org/xsa/advisory-375.html
        NOTE: 
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00516.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2673763353a97a065e37ccfbe251d13ba4350c0f...2cd1fa5c27b3ced116946de504b655d456922317

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2673763353a97a065e37ccfbe251d13ba4350c0f...2cd1fa5c27b3ced116946de504b655d456922317
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to