From ea0d6e72b1ba346264d25ab8bdd78f6551eaaadf Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 22 Sep 2024 06:41:59 +0000 Subject: [ GLSA 202409-10 ] Xen: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/918669 Bug: https://bugs.gentoo.org/921355 Bug: https://bugs.gentoo.org/923741 Bug: https://bugs.gentoo.org/928620 Bug: https://bugs.gentoo.org/929038 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202409-10.xml | 83 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 83 insertions(+) create mode 100644 glsa-202409-10.xml diff --git a/glsa-202409-10.xml b/glsa-202409-10.xml new file mode 100644 index 00000000..0ed4d142 --- /dev/null +++ b/glsa-202409-10.xml @@ -0,0 +1,83 @@ + + + + Xen: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in Xen, the worst of which could lead to privilege escalation. + xen + 2024-09-22 + 2024-09-22 + 918669 + 921355 + 923741 + 928620 + 929038 + remote + + + 4.17.4 + 4.17.4 + + + +

Xen is a bare-metal hypervisor.

+
+ +

Multiple vulnerabilities have been discovered in Xen. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Xen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.17.4" + +
+ + CVE-2022-4949 + CVE-2022-42336 + CVE-2023-28746 + CVE-2023-34319 + CVE-2023-34320 + CVE-2023-34321 + CVE-2023-34322 + CVE-2023-34323 + CVE-2023-34324 + CVE-2023-34325 + CVE-2023-34327 + CVE-2023-34328 + CVE-2023-46835 + CVE-2023-46836 + CVE-2023-46837 + CVE-2023-46839 + CVE-2023-46840 + CVE-2023-46841 + CVE-2023-46842 + CVE-2024-2193 + CVE-2024-31142 + XSA-431 + XSA-432 + XSA-436 + XSA-437 + XSA-438 + XSA-439 + XSA-440 + XSA-441 + XSA-442 + XSA-447 + XSA-449 + XSA-450 + XSA-451 + XSA-452 + XSA-453 + XSA-454 + XSA-455 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad