Summary: | <app-emulation/xen{-tools}-4.6.0-r8: PV superpage functionality missing sanity checks (XSA-167) (CVE-2016-1570) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Kristian Fiskerstrand (RETIRED) <k_f> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | arm, idella4 |
Priority: | Normal | Keywords: | STABLEREQ |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
See Also: | https://bugs.gentoo.org/show_bug.cgi?id=571556 | ||
Whiteboard: | C2 [glsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Kristian Fiskerstrand (RETIRED)
![]() Updated resolution to be precise in patch naming Almost: xsa167.patch xen-unstable xsa167-4.6.patch Xen 4.6.x, 4.5.x xsa167-4.4.patch Xen 4.4.x, 4.3.x Will be fixed in next version sent out. Public release commit 355e4fcbd3f83ef4b3d435e843503033d1a8c3b8 Author: Ian Delaney <idella4@gentoo.org> Date: Thu Jan 21 22:07:07 2016 +0800 app-emulation/xen: revbumps to vns. 4.5.2-r4 4.6.0-r8 wrt gentoo security bug. patches added; xsa 167-4.6, xsa168 Purging of led version to await stabilsation of revbumped vns. Gentoo bug: #571556, #571552 Arches please stabilise Arches =app-emulation/xen-4.5.2-r4 amd64 arm =app-emulation/xen-4.6.0-r8 amd64 arm =app-emulation/xen-tools-4.5.2-r4 amd64 arm x86 =app-emulation/xen-tools-4.6.0-r7 amd64 arm x86 The irregularity here is that xen-tools is still to be set stable for the first time. I have no insight into how or way there is difficulty or delay in that, but if there is I have had no such notification. I will await full stabilisation for clearing vulnerable version This can serve for #571556 Need also include commit dd9ecb826db3250e60c35d188804cb16cf0a6dde Author: Ian Delaney <idella4@gentoo.org> Date: Thu Jan 21 22:03:25 2016 +0800 app-emulation/xen-tools: revbumps to vns. 4.5.2-r4 4.6.0-r7 wrt gentoo security bug. patches added; xsa 167-4.6, xsa168 Purging of led version to await stabilsation of revbumped vns. Gentoo bug: #571556, #571552 amd64 stable x86 stable Added to existing GLSA. This issue was resolved and addressed in GLSA 201604-03 at https://security.gentoo.org/glsa/201604-03 by GLSA coordinator Yury German (BlueKnight). |