Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 699996 (XSA-304, XSA-305) - <app-emulation/xen-4.11.2-r2: multiple vulnerabilities (XSA-{304,305})
Summary: <app-emulation/xen-4.11.2-r2: multiple vulnerabilities (XSA-{304,305})
Status: RESOLVED FIXED
Alias: XSA-304, XSA-305
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://xenbits.xen.org/xsa/advisory-...
Whiteboard: B3 [glsa+ cve]
Keywords:
: 699990 (view as bug list)
Depends on:
Blocks: CVE-2018-12207 CVE-2019-11135
  Show dependency tree
 
Reported: 2019-11-13 10:57 UTC by GLSAMaker/CVETool Bot
Modified: 2020-03-25 20:48 UTC (History)
3 users (show)

See Also:
Package list:
app-emulation/xen-4.11.2-r2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2019-11-13 10:57:03 UTC
CVE-2019-11135 (https://nvd.nist.gov/vuln/detail/CVE-2019-11135):
  A flaw was found in the implementation of Intel Transactional
  Synchronization Extensions (TSX) abortion where a local authenticated
  attacker with the ability to monitor execution time is able to infer TSX
  memory state by comparing abort execution times.
Comment 2 Tomáš Mózes 2019-11-13 15:12:16 UTC
*** Bug 699990 has been marked as a duplicate of this bug. ***
Comment 3 Agostino Sarubbo gentoo-dev 2019-11-14 12:30:21 UTC
amd64 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 4 Larry the Git Cow gentoo-dev 2019-11-14 15:18:29 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=42d847bafda98ec12728acdd9bca716336ae248f

commit 42d847bafda98ec12728acdd9bca716336ae248f
Author:     Yixun Lan <dlan@gentoo.org>
AuthorDate: 2019-11-14 15:17:01 +0000
Commit:     Yixun Lan <dlan@gentoo.org>
CommitDate: 2019-11-14 15:18:02 +0000

    app-emulation/xen: cleanup & drop vulnerable version
    
    Fix XSA-{304,305}
    
    Bug: https://bugs.gentoo.org/699996
    Package-Manager: Portage-2.3.78, Repoman-2.3.17
    Signed-off-by: Yixun Lan <dlan@gentoo.org>

 app-emulation/xen/Manifest             |   1 -
 app-emulation/xen/xen-4.11.2-r1.ebuild | 154 ---------------------------------
 2 files changed, 155 deletions(-)
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-25 20:36:18 UTC
Added to an existing GLSA.
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2020-03-25 20:48:09 UTC
This issue was resolved and addressed in
 GLSA 202003-56 at https://security.gentoo.org/glsa/202003-56
by GLSA coordinator Thomas Deutschmann (whissi).