-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 20 Dec 2024 18:46:37 +0100 Source: xen Binary: libxen-dev libxencall1 libxencall1-dbgsym libxendevicemodel1 libxendevicemodel1-dbgsym libxenevtchn1 libxenevtchn1-dbgsym libxenforeignmemory1 libxenforeignmemory1-dbgsym libxengnttab1 libxengnttab1-dbgsym libxenhypfs1 libxenhypfs1-dbgsym libxenmisc4.17 libxenmisc4.17-dbgsym libxenstore4 libxenstore4-dbgsym libxentoolcore1 libxentoolcore1-dbgsym libxentoollog1 libxentoollog1-dbgsym xen-doc xen-hypervisor-4.17-armhf xen-hypervisor-4.17-armhf-dbg xen-hypervisor-common xen-system-armhf xen-utils-4.17 xen-utils-4.17-dbg xen-utils-common xen-utils-common-dbgsym xenstore-utils xenstore-utils-dbgsym Architecture: armhf Version: 4.17.5+23-ga4e5191dc0-1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Hans van Kranenburg Description: libxen-dev - Public headers and libs for Xen libxencall1 - Xen runtime library - libxencall libxendevicemodel1 - Xen runtime libraries - libxendevicemodel libxenevtchn1 - Xen runtime libraries - libxenevtchn libxenforeignmemory1 - Xen runtime libraries - libxenforeignmemory libxengnttab1 - Xen runtime libraries - libxengnttab libxenhypfs1 - Xen runtime library - libxenhypfs libxenmisc4.17 - Xen runtime libraries - miscellaneous, versioned ABI libxenstore4 - Xen runtime libraries - libxenstore libxentoolcore1 - Xen runtime libraries - libxentoolcore libxentoollog1 - Xen runtime libraries - libxentoollog xen-doc - Xen documentation xen-hypervisor-4.17-armhf - Xen Hypervisor on ARMHF xen-hypervisor-4.17-armhf-dbg - debug symbols for Xen Hypervisor on ARMHF xen-hypervisor-common - Xen Hypervisor - common files xen-system-armhf - Xen System on ARMHF (metapackage) xen-utils-4.17 - Xen administrative tools xen-utils-4.17-dbg - debug symbols for xen-utils-4.17 xen-utils-common - Xen administrative tools - common files xenstore-utils - Xenstore command line utilities for Xen Changes: xen (4.17.5+23-ga4e5191dc0-1) bookworm-security; urgency=medium . * Update to new upstream version 4.17.5+23-ga4e5191dc0, which also contains security fixes for the following issues: - x86: shadow stack vs exceptions from emulation stubs XSA-451 CVE-2023-46841 - x86: Register File Data Sampling XSA-452 CVE-2023-28746 - GhostRace: Speculative Race Conditions XSA-453 CVE-2024-2193 - x86 HVM hypercalls may trigger Xen bug check XSA-454 CVE-2023-46842 - x86: Incorrect logic for BTC/SRSO mitigations XSA-455 CVE-2024-31142 - x86: Native Branch History Injection XSA-456 CVE-2024-2201 - double unlock in x86 guest IRQ handling XSA-458 CVE-2024-31143 - error handling in x86 IOMMU identity mapping XSA-460 CVE-2024-31145 - PCI device pass-through with shared resources XSA-461 CVE-2024-31146 - x86: Deadlock in vlapic_error() XSA-462 CVE-2024-45817 - Deadlock in x86 HVM standard VGA handling XSA-463 CVE-2024-45818 - libxl leaks data to PVH guests via ACPI tables XSA-464 CVE-2024-45819 * Note that the following XSA are not listed, because... - XSA-457 and XSA-465 have patches for the Linux kernel. - XSA-459 is within Xapi which is not shipped by this package. - XSA-466 contains a documentation update that was only applied to the current development version of Xen Checksums-Sha1: 14c8c388c1c6c91324b540f2943a0be79eaab663 698372 libxen-dev_4.17.5+23-ga4e5191dc0-1_armhf.deb 3803b370508d5f89c9aa4b428a64dc6e8628f19e 12660 libxencall1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb e035eef1f40d97a45b67cd6d8f7745bb7fc5d6b8 32304 libxencall1_4.17.5+23-ga4e5191dc0-1_armhf.deb f88b6148628bdcbfabe483b72164058e5388291e 18184 libxendevicemodel1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 99c8fc708b959155e0dbc157434f626521593a5a 33152 libxendevicemodel1_4.17.5+23-ga4e5191dc0-1_armhf.deb c78e0594eb4ba24bd2667c7d46a9f31c84aae63f 8404 libxenevtchn1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 8bc7457793ae7a6ff82f0a8cb6cf008f22d9deb6 31052 libxenevtchn1_4.17.5+23-ga4e5191dc0-1_armhf.deb 0a92a45cb82e4183da0ed85e71df8f52932e5350 14512 libxenforeignmemory1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 88e6e727c0f7bbff68cbd7b52f930d97d01979c8 32500 libxenforeignmemory1_4.17.5+23-ga4e5191dc0-1_armhf.deb 63f3a452638a7ec809728b7d79562c9516e2f8ea 17788 libxengnttab1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 805928280af46eb61db2749b8ccf97428298da10 32780 libxengnttab1_4.17.5+23-ga4e5191dc0-1_armhf.deb 0767264504ff3fe4eb963a041e40afe9145688bc 11984 libxenhypfs1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb f67996264cb77dc30c53b45b11e048d757b4f0fc 32492 libxenhypfs1_4.17.5+23-ga4e5191dc0-1_armhf.deb 387f46709bbe7bea1a29f62484dcee1647f82388 1492248 libxenmisc4.17-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb e64cbc0bcb4adb0d3980dce6b5a044d75613243f 386436 libxenmisc4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb 4627dbe3be88d7ef8b3fb435ab6d7660be4c0dc8 33988 libxenstore4-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 492054bff67e4c81b9a15677ea1882b7cbddbbc3 37552 libxenstore4_4.17.5+23-ga4e5191dc0-1_armhf.deb 2c1e626da798209bc02bf84161339d955450ddb0 5528 libxentoolcore1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb ac9f6ba9ff76be57f72609a448a7d8afd8b84458 30404 libxentoolcore1_4.17.5+23-ga4e5191dc0-1_armhf.deb 17ca7a706a13e76ba67869468e745b288b1c5f55 10316 libxentoollog1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 1e8b8df7c0e3ef69e615bc0662f3c758eff7c1f9 32180 libxentoollog1_4.17.5+23-ga4e5191dc0-1_armhf.deb 4b71bb4312fa944444bfe4e310808f364ba2a51c 535420 xen-doc_4.17.5+23-ga4e5191dc0-1_armhf.deb e809fe40ed00f3e60d5fa41f8be9599afb8c2aa7 338804 xen-hypervisor-4.17-armhf-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb 464f6d086a4f67ddb362aaf4b30b697374cedc18 285828 xen-hypervisor-4.17-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb 67115d890548db108bb1e2eb7d8185bdfd9db5cf 31772 xen-hypervisor-common_4.17.5+23-ga4e5191dc0-1_armhf.deb edc776959ec47078d0dcdd19b6d37deb7a903d11 28516 xen-system-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb c144b4b6d81bf002204aed73d2aa6a9befeb9d96 892764 xen-utils-4.17-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb 69a59ab7a066606b9e49fe88edafa65d1f2a42b3 650328 xen-utils-4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb 64774d55642a305fefb361f12baea75fa38c946f 206544 xen-utils-common-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb c46bec428d88953bce74a351e1faca5b4c25148c 262352 xen-utils-common_4.17.5+23-ga4e5191dc0-1_armhf.deb 17a72402d1776c53fe7c6d4a7e0ddfd903e55f5c 18630 xen_4.17.5+23-ga4e5191dc0-1_armhf-buildd.buildinfo 7bb1d45cb3047ced00fa33e99aedd30830ff31e7 20648 xenstore-utils-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 6c9b00a41ba48a461d78683169d8a950d21a6655 47248 xenstore-utils_4.17.5+23-ga4e5191dc0-1_armhf.deb Checksums-Sha256: ff6e4ad9c69e6bb258a4f4bd90223ad9eb6c28570545cea551a7f3b3de054098 698372 libxen-dev_4.17.5+23-ga4e5191dc0-1_armhf.deb 4fef7525a95ad47cfc9506e1b5e7812bc9b9cb39a90e4a12d970c5213d5239b1 12660 libxencall1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb b371e0672c88343b1761cec4d4c355324997ba02dcbf58edc605dc406ebc5830 32304 libxencall1_4.17.5+23-ga4e5191dc0-1_armhf.deb 8553ac12c75df47abce5b6a84a10469cf4ff0baf4506a317eade87380a05e87f 18184 libxendevicemodel1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 37e968915158623d234ec9e3fda0c7ffcf7be9e0f64382ad8554cf692852703a 33152 libxendevicemodel1_4.17.5+23-ga4e5191dc0-1_armhf.deb e58cd7a3d643d86d9331242f50bd1d6a82e85b18033f9bfde79d5f37400b2559 8404 libxenevtchn1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 2f3a6ff2f2170d7612798dec1e47892b8d7800a5c3234fe3b18a039cd28e71a3 31052 libxenevtchn1_4.17.5+23-ga4e5191dc0-1_armhf.deb 216abf198e1a4456d7f78691ac28b20ab672b458cb17a182a0d1dad327db3ce4 14512 libxenforeignmemory1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb ff1e0a502cb051c8561b9d886e38812d204e883122e4f045f38df24c64422d13 32500 libxenforeignmemory1_4.17.5+23-ga4e5191dc0-1_armhf.deb 734ab7930a2cc1a3fa3cc3c6744b4e5a15d2de851680739d9f57ff032cae0aca 17788 libxengnttab1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb fa611eb91fba43371d969e788c732bf462b6640f5730a6ac87ac7195770b860f 32780 libxengnttab1_4.17.5+23-ga4e5191dc0-1_armhf.deb 1d1bbfb771dce227e2939e10b37b36afcf38fe893236947183f466058c473912 11984 libxenhypfs1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 487f5971771af8985668a4872eb06853e91550d51bb247c5ab104056484eb223 32492 libxenhypfs1_4.17.5+23-ga4e5191dc0-1_armhf.deb 87a217a5a2c92e2fa93fdf7a37acc01b01c45bada21c406bcadf2babd2e8fb07 1492248 libxenmisc4.17-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb d6f10b2e8306971694d10d9c2b1fd17a98d538f020c21b236bcf4fbda4f2b11a 386436 libxenmisc4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb 739208f11447d3405e984486b8092db62b4e83604aececa04b0cb06bf165e242 33988 libxenstore4-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 8e9892348712d85c0c2a781577c7cd1b91290a2a3a591823f7c34be2e95ec1d4 37552 libxenstore4_4.17.5+23-ga4e5191dc0-1_armhf.deb c756d0b96e48f1fcdaae2b0357b85300c4ec299ca97f6cbe8423d1cdbeca1adb 5528 libxentoolcore1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb db71a56ecf6edab09e9e0aadb343f7b9b9c5af38639d2b512c95387fc9667d20 30404 libxentoolcore1_4.17.5+23-ga4e5191dc0-1_armhf.deb c725d13075f0c0ff4258c139b55b5ed9caebf6986f855ae2752d86d978fcd531 10316 libxentoollog1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 99d91a2dd21d797b530a51b5fc2f08f29cecb542ff9a95096efc18ccd3a6fd67 32180 libxentoollog1_4.17.5+23-ga4e5191dc0-1_armhf.deb ab90a267e930211b3f542df57539d8a337ff9198f23059afee8e6846ae135d6f 535420 xen-doc_4.17.5+23-ga4e5191dc0-1_armhf.deb 1343142f8b69d3bbb3c43e7726d27be40257b47bc231100ff1f9d9bef727ca39 338804 xen-hypervisor-4.17-armhf-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb e7571f43681a8a9275e41b3c47f1d6fc77409740a981ad65d153bd789a3e921f 285828 xen-hypervisor-4.17-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb 0518073a34e8466d3fb3825a4053a5e6be819b23674d507f2729098248d652e5 31772 xen-hypervisor-common_4.17.5+23-ga4e5191dc0-1_armhf.deb 6ffc118bf0a70b4f9112007215d3fee1647c646115ad6776994cbf2a4bdf67ac 28516 xen-system-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb 1a7d83a35547258b24d8dca681ee556dcb39ec40b2abadb212ea727320ceb5e4 892764 xen-utils-4.17-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb 73d0f2dd8db91a63972dc1f7c175ee75a33ed23da86502a2044ae86dd39ca8ba 650328 xen-utils-4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb 872768f0eac23d8df815d674073f10a0c1efcf1936fa60fe80ce032d6ec506d4 206544 xen-utils-common-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb a749908ef737b23f793eb1c9e129cafdfc62426a14a9d1230a557a3716f723e8 262352 xen-utils-common_4.17.5+23-ga4e5191dc0-1_armhf.deb 83e8a9c196fc6096a437f541520659ab5fb410cca1cee31e99aad6e99e5847fb 18630 xen_4.17.5+23-ga4e5191dc0-1_armhf-buildd.buildinfo 0924e8dddc259d924b4717c39c791e39b392e3aab151c6b4cb66e77bda3767c7 20648 xenstore-utils-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 3c928bf21d9dc89c88bbaf689014ad61413b68a14339d67706db7e07008bbc06 47248 xenstore-utils_4.17.5+23-ga4e5191dc0-1_armhf.deb Files: a2c3eb0a8082d4f06da889ac93e768ec 698372 libdevel optional libxen-dev_4.17.5+23-ga4e5191dc0-1_armhf.deb ead6ea5749d0cad354fa20546a542fd5 12660 debug optional libxencall1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 525532321d3877f394efbbe32165b980 32304 libs optional libxencall1_4.17.5+23-ga4e5191dc0-1_armhf.deb 5c4ef39c3cffb5ed9d6b1117ebb5b916 18184 debug optional libxendevicemodel1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 3794cec76f8945f532ba1ea69d5a48d1 33152 libs optional libxendevicemodel1_4.17.5+23-ga4e5191dc0-1_armhf.deb 0281810b8f16d58266e072ecce9b7cd4 8404 debug optional libxenevtchn1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb acc9750683f3fbcd705c210877e9fbd2 31052 libs optional libxenevtchn1_4.17.5+23-ga4e5191dc0-1_armhf.deb 32ae7e37ce46a454af9c15e710e6159e 14512 debug optional libxenforeignmemory1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 224acfc5dd57c714c472ed6fa67e0566 32500 libs optional libxenforeignmemory1_4.17.5+23-ga4e5191dc0-1_armhf.deb 8d5033843abc740d8891873daa08757f 17788 debug optional libxengnttab1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb e17381e2d20fc96b368dd31ad3e8ac81 32780 libs optional libxengnttab1_4.17.5+23-ga4e5191dc0-1_armhf.deb 4360e76c0b521c137efef35ec20d874d 11984 debug optional libxenhypfs1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb a5b2795d61ce3c8eb68ce9478097956c 32492 libs optional libxenhypfs1_4.17.5+23-ga4e5191dc0-1_armhf.deb 12c67fcaeea97e849c8527e4efdd78f5 1492248 debug optional libxenmisc4.17-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 9a5947f90a834b0aebc64ee6e55f77a5 386436 libs optional libxenmisc4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb 3cee8d0171eb26baeb057836d7905fdf 33988 debug optional libxenstore4-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 4ff941e004ecb289c06b4810b87dbfd5 37552 libs optional libxenstore4_4.17.5+23-ga4e5191dc0-1_armhf.deb d7a7df087e9ffc5f16794241e6f19c05 5528 debug optional libxentoolcore1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 89340ec9e999d71fb10d65b65843b4fa 30404 libs optional libxentoolcore1_4.17.5+23-ga4e5191dc0-1_armhf.deb e6d465c41fabd53dc343b628bd3e706c 10316 debug optional libxentoollog1-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 11b6d3c2b346d3f62fd0558712a82a96 32180 libs optional libxentoollog1_4.17.5+23-ga4e5191dc0-1_armhf.deb 0e88498b02e14740cf3e02b688b3e62b 535420 doc optional xen-doc_4.17.5+23-ga4e5191dc0-1_armhf.deb b0206f5fddcf859d5502bc8c67cbd8cc 338804 debug optional xen-hypervisor-4.17-armhf-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb 2662ac88868f251f50a8a50d88061bb0 285828 kernel optional xen-hypervisor-4.17-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb 5d39843e5f48bd87f43eab4e22170361 31772 kernel optional xen-hypervisor-common_4.17.5+23-ga4e5191dc0-1_armhf.deb 1faaa74cfbe3ff36ecfa8af8794be04a 28516 admin optional xen-system-armhf_4.17.5+23-ga4e5191dc0-1_armhf.deb 4c098f198a4339aea3543e668230af1d 892764 debug optional xen-utils-4.17-dbg_4.17.5+23-ga4e5191dc0-1_armhf.deb 9980865f82bb215f80173613524dfde2 650328 admin optional xen-utils-4.17_4.17.5+23-ga4e5191dc0-1_armhf.deb c98cea358b6c12cb6e5a62e0651b6315 206544 debug optional xen-utils-common-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 8adf9eaf51becc0814181b9931824061 262352 admin optional xen-utils-common_4.17.5+23-ga4e5191dc0-1_armhf.deb 66a585452d362dc16237be8a2985e951 18630 admin optional xen_4.17.5+23-ga4e5191dc0-1_armhf-buildd.buildinfo c22fe69279ac4a5b63ee4a019af8aa45 20648 debug optional xenstore-utils-dbgsym_4.17.5+23-ga4e5191dc0-1_armhf.deb 6024f2051426885d20dd6cf0eb192f06 47248 admin optional xenstore-utils_4.17.5+23-ga4e5191dc0-1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmdpcFkACgkQ4CwlMGxH D8Wy6Q/7BdpNhu7ZoWzB34b2jobydPG7yqwj5bDrx1t23QjAlN/hlGrAMxmw50XU OWflGMkWnvgfZUNlZZsU3Bl+jn+z7ZywxdXTIfDQiO4PpDWpVCzrkkI2trzhrRcI N8pVtxDX5EPrzC7yLc7WcEyy/00WBc+xEmkkx8JGh8Y7trvjHOESZOxnRuuMUTFz 6RbFr/REM9xR5DBLPLoFcGVpJMbMRORsJ2Y8XUTHTCNAxuJ9vxxBirSqe6FVSUcY 61K982RMXr2azsnQK5EAaDgJiqe1kI8IXbs4iKzwTpMeMRpF2IFkEiS9TUeGMVpP R4NUxybMndWLoWavTAyXGsd0ApH4PMW19LgpU3sR9wBvS2MvzGFy4ycRYU2ZSiTr YI1mGknHDef9oae/ibKi8DhDZPmTDa2gwlFIhUxJCLbLSO/PCLDhjS5agwmn+4Vc DvjINpzCQOAlU3EKKemuw8ecavmHKC6sXm54SMTY0S6CGGZmGgJm1YB1J31xtM1S Dzgx4zCFIeHuursODjT1dPPUFipddwdsLEHUh9vPyy2xajbdLzpLCj7rpmIRHXns RR1AvZuTlvo0di0wwzVvycLZQXoTRX14JSAZXptJqRQOBdrgcxBrxmy7TtkFcdOj uPFxNXSvJc4kikLpsPoj/ybfHSLvf3LNTk13QJDUG3hP6XjqUkY= =GnjI -----END PGP SIGNATURE-----