Summary: | <app-emulation/xen-{4.13.2-r4,4.14.1}: host DoS via malicious guest (XSA-360, CVE-2021-3308) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | hydrapolic, proxy-maint, xen |
Priority: | Normal | Keywords: | PullRequest |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://markmail.org/message/bcic2rku2hg4dafb | ||
See Also: |
https://github.com/gentoo/gentoo/pull/19128 https://github.com/gentoo/gentoo/pull/19330 |
||
Whiteboard: | B3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
2021-01-22 02:45:05 UTC
Please proceed with stabilization when ready, thanks! Sanity check failed:
> app-emulation/xen-4.14.1
> pdepend amd64 dev profile default/linux/amd64/17.0/x32 (2 total)
> ~app-emulation/xen-tools-4.14.1
> pdepend amd64 stable profile default/linux/amd64/17.1 (14 total)
> ~app-emulation/xen-tools-4.14.1
All sanity-check issues have been resolved amd64 done all arches done Not sure how I missed CCing maintainers... Please cleanup. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=307e92ec30fa21aafd600f9788a23d6cb759c357 commit 307e92ec30fa21aafd600f9788a23d6cb759c357 Author: Tomáš Mózes <hydrapolic@gmail.com> AuthorDate: 2021-02-04 19:08:56 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2021-02-04 22:23:39 +0000 app-emulation/xen: drop vulnerable Bug: https://bugs.gentoo.org/766474 Bug: https://bugs.gentoo.org/760144 Signed-off-by: Tomáš Mózes <hydrapolic@gmail.com> Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> app-emulation/xen/Manifest | 4 - app-emulation/xen/xen-4.13.2-r2.ebuild | 165 --------------------------------- app-emulation/xen/xen-4.13.2-r3.ebuild | 165 --------------------------------- app-emulation/xen/xen-4.14.0-r7.ebuild | 165 --------------------------------- 4 files changed, 499 deletions(-) GLSA request filed. This issue was resolved and addressed in GLSA 202107-30 at https://security.gentoo.org/glsa/202107-30 by GLSA coordinator Sam James (sam_c). |