Summary: | <app-emulation/xen-{tools-}{4.5.2-r2,4.6.0-r3}: Multiple Vulnerabilities (XSA-{159,160}) (CVE-2015-{8339,8340,8341}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Yury German <blueknight> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | dlan, idella4 |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 561110, 564472 |
Description
Yury German
![]() ![]() Patches have been sent to xen maintainers. commit cec1b419cc9c56d2573a858a6c6e727f97d924a4 Author: Ian Delaney <idella4@gentoo.org> Date: Wed Dec 9 13:28:39 2015 +0800 clean vulnerable vns. wrt #566842 #566844 Package-Manager: portage-2.2.24 commit d20b6d3f4e02313651ce37098087215e2e8ad92c Author: Ian Delaney <idella4@gentoo.org> Date: Wed Dec 9 13:26:20 2015 +0800 app-emulation/xen-tools: revbumps -> vns. 4.5.2-r2, 4.6.0-r3 wrt sec. bugs Addition of patches XSA-158 (#566844), XSA-{159,160} (#566842), fixing all corresponding security issues, patches made avaialable for public release as of yesterday (08/12). Patches compressed into my devspace then combined with those of dlan insource. This format will do for now. Not to be adjusted without prior discussion. All patches pass runtests Gentoo bugs: #566842 #566844 Is 4.5.2-r2 ready to go to stable? (In reply to Agostino Sarubbo from comment #3) > Is 4.5.2-r2 ready to go to stable? Yes please ago, make it stable Arch; amd64 amd64 stable. Maintainer(s), please cleanup. Security, please vote. (In reply to Agostino Sarubbo from comment #5) > amd64 stable. > > Maintainer(s), please cleanup. > Security, please vote. ago slight misunderstanding, title app-emulation/xen implicates xen only. xen-tools-4.5.2-r2 also requires making stable. xen / xen-tools are typically both drawn in, rarely xen-pvgrub. Will wait for this before cleaning both. Target: amd64 Arches, please test and mark stable: =app-emulation/xen-tools-4.5.2-r2 Target Keywords : "amd64 x86" Thank you! Resetting Stabilization for the xen-tools, as per maintainer. (In reply to Ian Delaney from comment #6) > ago slight misunderstanding, title app-emulation/xen implicates xen only. > xen-tools-4.5.2-r2 also requires making stable. xen / xen-tools are > typically both drawn in, rarely xen-pvgrub. Will wait for this before > cleaning both. Next time please use the form used by Yury in comment #7 (In reply to Yury German from comment #7) > Arches, please test and mark stable: > > =app-emulation/xen-tools-4.5.2-r2 > > Target Keywords : "amd64 x86" > > Thank you! > > Resetting Stabilization for the xen-tools, as per maintainer. x86 has nothing to do here. amd64 stable. Maintainer(s), please cleanup. Security, please vote. commit 15376b7a9fc87586a7767a2f5456dd861d9d0028 Author: Ian Delaney <idella4@gentoo.org> Date: Wed Dec 23 08:22:13 2015 +0800 app-emulation/xen-tools: clean vn. 4.5.2-r1 re sec bug #566842 commit 59aef5a6741547b1c8a27ac7feebe6a307f7aa15 Author: Ian Delaney <idella4@gentoo.org> Date: Wed Dec 23 08:19:16 2015 +0800 app-emulation/xen: clean vn. 4.5.2-r1 re sec bug #566842 Please Clean or Mask - app-emulation/xen-tools 4.2.5-r11, 4.2.5-r10. Setting dependency for all other cleanup for xen-tools against this bug. masking them breaks rdep qemu atm This issue was resolved and addressed in GLSA 201604-03 at https://security.gentoo.org/glsa/201604-03 by GLSA coordinator Yury German (BlueKnight). |