-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 11 Dec 2020 22:10:09 +0100 Source: xen Binary: libxen-dev libxencall1 libxencall1-dbgsym libxendevicemodel1 libxendevicemodel1-dbgsym libxenevtchn1 libxenevtchn1-dbgsym libxenforeignmemory1 libxenforeignmemory1-dbgsym libxengnttab1 libxengnttab1-dbgsym libxenmisc4.11 libxenmisc4.11-dbgsym libxenstore3.0 libxenstore3.0-dbgsym libxentoolcore1 libxentoolcore1-dbgsym libxentoollog1 libxentoollog1-dbgsym xen-doc xen-hypervisor-4.11-amd64 xen-system-amd64 xen-utils-4.11 xen-utils-4.11-dbgsym xen-utils-common xen-utils-common-dbgsym xenstore-utils xenstore-utils-dbgsym Architecture: i386 Version: 4.11.4+57-g41a822c392-2 Distribution: buster-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Hans van Kranenburg Description: libxen-dev - Public headers and libs for Xen libxencall1 - Xen runtime library - libxencall libxendevicemodel1 - Xen runtime libraries - libxendevicemodel libxenevtchn1 - Xen runtime libraries - libxenevtchn libxenforeignmemory1 - Xen runtime libraries - libxenforeignmemory libxengnttab1 - Xen runtime libraries - libxengnttab libxenmisc4.11 - Xen runtime libraries - miscellaneous, versioned ABI libxenstore3.0 - Xen runtime libraries - libxenstore libxentoolcore1 - Xen runtime libraries - libxentoolcore libxentoollog1 - Xen runtime libraries - libxentoollog xen-doc - XEN documentation xen-hypervisor-4.11-amd64 - Xen Hypervisor on AMD64 xen-system-amd64 - Xen System on AMD64 (metapackage) xen-utils-4.11 - XEN administrative tools xen-utils-common - Xen administrative tools - common files xenstore-utils - Xenstore command line utilities for Xen Changes: xen (4.11.4+57-g41a822c392-2) buster-security; urgency=high . * Apply security fixes for the following issues: - oxenstored: permissions not checked on root node XSA-353 (CVE-2020-29479) - xenstore watch notifications lacking permission checks XSA-115 (CVE-2020-29480) - Xenstore: new domains inheriting existing node permissions XSA-322 (CVE-2020-29481) - Xenstore: wrong path length check XSA-323 (CVE-2020-29482) - Xenstore: guests can crash xenstored via watchs XSA-324 (CVE-2020-29484) - Xenstore: guests can disturb domain cleanup XSA-325 (CVE-2020-29483) - oxenstored memory leak in reset_watches XSA-330 (CVE-2020-29485) - oxenstored: node ownership can be changed by unprivileged clients XSA-352 (CVE-2020-29486) - undue recursion in x86 HVM context switch code XSA-348 (CVE-2020-29566) - FIFO event channels control block related ordering XSA-358 (CVE-2020-29570) - FIFO event channels control structure ordering XSA-359 (CVE-2020-29571) * Note that the following XSA are not listed, because... - XSA-349 and XSA-350 have patches for the Linux kernel - XSA-354 has patches for the XAPI toolstack - XSA-356 only applies to Xen 4.14 Checksums-Sha1: 66e0fe08e0c90da4f9fa6ad9c3c1e021311ed904 767348 libxen-dev_4.11.4+57-g41a822c392-2_i386.deb edccc592b32091e176e52c560797e3686c788d31 12560 libxencall1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 13aa1778ad7526a08358490a0346e1cf579d9f4c 35508 libxencall1_4.11.4+57-g41a822c392-2_i386.deb 126f8136e4a67255192927b21b9cbf2a57f6d408 15844 libxendevicemodel1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb d7a2a29f8f7489f73e677eead5fc9bb4eeea55fa 36956 libxendevicemodel1_4.11.4+57-g41a822c392-2_i386.deb 704f5c3636d3d5d63cedc1799553c92c3b026c24 7968 libxenevtchn1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 1f6f88ad2937f95bd245997d595f2e504879cbcc 33716 libxenevtchn1_4.11.4+57-g41a822c392-2_i386.deb a065c962b9b71cb51edb19b1c03cc5ddb7c31d3d 11600 libxenforeignmemory1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 6ca33e0a70d59be37487b0d6abd9867528c37f21 35596 libxenforeignmemory1_4.11.4+57-g41a822c392-2_i386.deb 957afb4f7dd295b6eaaed1b59afb95ffcd8532b1 13312 libxengnttab1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb e6c5dfc9f676c8e64e54f4e36c64c6c8fda2667a 35640 libxengnttab1_4.11.4+57-g41a822c392-2_i386.deb 07b1641a42930fdf0f50f5714278eb0f69fedb9f 2166952 libxenmisc4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 9b7cb20cf42f71a1933a2b6e800c397e09b2cfd8 503000 libxenmisc4.11_4.11.4+57-g41a822c392-2_i386.deb f6e7b9389222222b3790d7b3cad43222c6ca5141 32128 libxenstore3.0-dbgsym_4.11.4+57-g41a822c392-2_i386.deb d4086cefba17a9ba2f9890bcaec3c02e60e3ed22 43248 libxenstore3.0_4.11.4+57-g41a822c392-2_i386.deb 71707fce3ab2d89204617b90eb6bbaa6771f8f66 5004 libxentoolcore1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb b1f41e6bd15dabf3944d5094b08bfc9e5b8003c0 33032 libxentoolcore1_4.11.4+57-g41a822c392-2_i386.deb c96e62b1c5df280c6ef21c8958f504b60bec6d56 9848 libxentoollog1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb d8f9329743e2728783ca77cd5f2cc13f6a0db016 34776 libxentoollog1_4.11.4+57-g41a822c392-2_i386.deb d70b2458b9772112b63d6a048cd200522ea8f119 434916 xen-doc_4.11.4+57-g41a822c392-2_i386.deb 9ac3b8963bdd2a7b319a76c2457477dbb3d1b2f3 15068220 xen-hypervisor-4.11-amd64_4.11.4+57-g41a822c392-2_i386.deb dd03626a413e4c983b700282216a06ee7dbcae62 30856 xen-system-amd64_4.11.4+57-g41a822c392-2_i386.deb 4e6aa6246f2659dd32cb7c5a74ceb0cad0f00862 1042192 xen-utils-4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb bcd5ab5cdc40b51660fa67a2fdd25ad5ee1ad587 7121604 xen-utils-4.11_4.11.4+57-g41a822c392-2_i386.deb e08f2d0a7710117cc14af954415bd68fd88a2ae7 246520 xen-utils-common-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 8e5f87302403335bee02985f1065e44c279ab9fb 282652 xen-utils-common_4.11.4+57-g41a822c392-2_i386.deb b6f0233d5f7e44197e93d88a184f22e5d0b4dcac 17442 xen_4.11.4+57-g41a822c392-2_i386-buildd.buildinfo e4a21684c7e8fcfcb8bdc1b1045fe68b4d1a16c7 19356 xenstore-utils-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 3d27b17b2c7700a86d5b405aca82b2c647e83c68 45952 xenstore-utils_4.11.4+57-g41a822c392-2_i386.deb Checksums-Sha256: f9937e9b2dd649d78345c203cd24e95d313ef91ff2b6f3ff984c3c817f6000ae 767348 libxen-dev_4.11.4+57-g41a822c392-2_i386.deb 60cf4af1b2b4b7128530a6f5b3b11e88afd8acffb5f9d611d3cfda13cd7ddff8 12560 libxencall1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 352af629f771c0c37ad912c5c2db6a0b0a4ed52deaf3463c2f3b15e7fc4d1a55 35508 libxencall1_4.11.4+57-g41a822c392-2_i386.deb cf8b17451642e94719aacb2b85288a0bd3dfb20a68153037c0d5f9e217fdd5a5 15844 libxendevicemodel1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 76c8995b51b0906eedc655d8a55a76c33c453780ac64d9f41bf80f71e3e3e4cd 36956 libxendevicemodel1_4.11.4+57-g41a822c392-2_i386.deb 9d61490ce8c3026089f5e5fa9e7839e0affb0a03dc6b4b9b7648325139609e7a 7968 libxenevtchn1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb b228d417ff192b721d5867f45789280cd0bbf23bbd9805f5d24542a4511524e5 33716 libxenevtchn1_4.11.4+57-g41a822c392-2_i386.deb f41bb9e5acbc9568c5950264c179a2e05840d933bf7a467e8c9d1ff86e7c6ffe 11600 libxenforeignmemory1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 24b377663caf10b0f5c97d66739f8dbc33a66e636bcfce0d88ecbe4ce1eccc17 35596 libxenforeignmemory1_4.11.4+57-g41a822c392-2_i386.deb 2a80969d6701f58561238c50503f687cae903f1738484958ca24910121210ccb 13312 libxengnttab1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 3d493d03aca11a1bff4981650e49bac917fcf11ef020ea0cf6304afbebd3edf1 35640 libxengnttab1_4.11.4+57-g41a822c392-2_i386.deb 3fbdca7591080fb44098a81d793a3de414ad0022dd2d832c0d6cec6d9e0018de 2166952 libxenmisc4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb c4f99acaf4355eb2b785ebd50837ad79a2bb11dea9eac0dfcacd45f5a8509676 503000 libxenmisc4.11_4.11.4+57-g41a822c392-2_i386.deb cadb0b4415d3942ab75296572bca6c0c17b948199cc78a6886e514081ef7e399 32128 libxenstore3.0-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 8b6c1bc86cc39566cfdc7b99e19edc3fca82ba920fce93bf7a69987415884d43 43248 libxenstore3.0_4.11.4+57-g41a822c392-2_i386.deb 8ea26a3f786378086abd4d389eb6e38e41b85f039a0ba5a6dc0f7eeedb6a0ced 5004 libxentoolcore1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb e1a921580d5c38abab377f1e83a23ba6c0e0bb9b295969011b58be5b14184aab 33032 libxentoolcore1_4.11.4+57-g41a822c392-2_i386.deb 7e5194c9edd86e33424c9de8f27d46cf070fa6714f1827c55603e87334bdbef3 9848 libxentoollog1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb deaf6cf54db264afa4663ffa5fd827b904353863e751ed426cff6f15ef564491 34776 libxentoollog1_4.11.4+57-g41a822c392-2_i386.deb 2ba1ea5913aa683cf8866147e0656cab4beebe5abbd08f7584d7ce91fac1e950 434916 xen-doc_4.11.4+57-g41a822c392-2_i386.deb c119e86d5b598dd9b6378fc5c3f00dbfe805de44e0ba83f38ff772925c590dc0 15068220 xen-hypervisor-4.11-amd64_4.11.4+57-g41a822c392-2_i386.deb 49d5ba1062600be45d7c3f2141f350993f33877544c7d27ceb1a9bc7a334a4e9 30856 xen-system-amd64_4.11.4+57-g41a822c392-2_i386.deb ecbd0e7161ef07ad1fd88723da46d307abdccb17d7285795d9a64bd65d9a63ad 1042192 xen-utils-4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 3ba3d56795ccc6ddb94ebfbf8ee7c748058abed5a8e433fc86632e59b2ffc001 7121604 xen-utils-4.11_4.11.4+57-g41a822c392-2_i386.deb 92cd5890edc3c8fe898aed3829c9b3c17fc39f8020b21eca2cc104a980f10685 246520 xen-utils-common-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 684a95e2837d0797c288ad5b780f1eace0eee7cf08563c529b7e01ec0cea1332 282652 xen-utils-common_4.11.4+57-g41a822c392-2_i386.deb fbfab68579ced71afde94cfc3cec354ba5f45b71a8e51f130f0ef35a952ae208 17442 xen_4.11.4+57-g41a822c392-2_i386-buildd.buildinfo aaa9d3ad2643d84d1d282e2496ca4d723958828e22d7ee15024b5f14d8a28fca 19356 xenstore-utils-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 1776ec2401ad1344340ceefa26df61220f669a67e04814c433687fcdfccde9d3 45952 xenstore-utils_4.11.4+57-g41a822c392-2_i386.deb Files: a8bc425ceeafedeec07e288451385e16 767348 libdevel optional libxen-dev_4.11.4+57-g41a822c392-2_i386.deb 0fc3024757117c05ee65e645e0c3f7db 12560 debug optional libxencall1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 115dd467c6cddfe3d6947edfb6337c9f 35508 libs optional libxencall1_4.11.4+57-g41a822c392-2_i386.deb 859c54b49ca6f8360713958f0a63b162 15844 debug optional libxendevicemodel1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb d2bd35c2275b20a6867e8e4a88528e89 36956 libs optional libxendevicemodel1_4.11.4+57-g41a822c392-2_i386.deb 883058c83ede268fa8d3c00bcc935d41 7968 debug optional libxenevtchn1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 3a1b7c793dc566a23290ff9ccf67af35 33716 libs optional libxenevtchn1_4.11.4+57-g41a822c392-2_i386.deb e4d815c0b818f3d1339f9fe6b4fdc282 11600 debug optional libxenforeignmemory1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb be795e95b407dc8d02985db1f472a3a8 35596 libs optional libxenforeignmemory1_4.11.4+57-g41a822c392-2_i386.deb a9ab625dafba1a74ca57d3ac5387aa97 13312 debug optional libxengnttab1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb dc06e3f39df9d2328b9bb6163963931b 35640 libs optional libxengnttab1_4.11.4+57-g41a822c392-2_i386.deb 619b43c799035ad61be618adf5264df7 2166952 debug optional libxenmisc4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 37f042ae4b2358f31a777230cde03a6e 503000 libs optional libxenmisc4.11_4.11.4+57-g41a822c392-2_i386.deb f9713f31b8418f1d52eba1b0e55238b5 32128 debug optional libxenstore3.0-dbgsym_4.11.4+57-g41a822c392-2_i386.deb a6d4c96712e6d96e1c6e3226f2c9c4c4 43248 libs optional libxenstore3.0_4.11.4+57-g41a822c392-2_i386.deb 5ec6f526b23a3bba76631de6e275a8e8 5004 debug optional libxentoolcore1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 78428cf805ef9f69edd46c436cf6aa57 33032 libs optional libxentoolcore1_4.11.4+57-g41a822c392-2_i386.deb dd7c67afe78a9360ca826d8716034738 9848 debug optional libxentoollog1-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 953e9c2e8e077c86aa164dbebfb7811d 34776 libs optional libxentoollog1_4.11.4+57-g41a822c392-2_i386.deb 1a01ebece00ba9823c536adcf0f7cb16 434916 doc optional xen-doc_4.11.4+57-g41a822c392-2_i386.deb 22e969064cdabd39f233225cc9727b08 15068220 kernel optional xen-hypervisor-4.11-amd64_4.11.4+57-g41a822c392-2_i386.deb 4df7d340920c209c0073609bd65316a1 30856 admin optional xen-system-amd64_4.11.4+57-g41a822c392-2_i386.deb 025a6240dff1b48cf4632a7caca8352a 1042192 debug optional xen-utils-4.11-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 10a3513204f0fd7df3e5a7551aa62d15 7121604 admin optional xen-utils-4.11_4.11.4+57-g41a822c392-2_i386.deb 00a7cf57b0ef04c7e6c34b6ec5867806 246520 debug optional xen-utils-common-dbgsym_4.11.4+57-g41a822c392-2_i386.deb 0bfe1b4a916d2337945d552fbebff53c 282652 admin optional xen-utils-common_4.11.4+57-g41a822c392-2_i386.deb 6f0bf0452095d6d46fcc11a7a2791ff5 17442 admin optional xen_4.11.4+57-g41a822c392-2_i386-buildd.buildinfo 9f2a74c9d344ad31606eb632fa76c4ed 19356 debug optional xenstore-utils-dbgsym_4.11.4+57-g41a822c392-2_i386.deb d0ad6692607ff7d3e3c3202086326ddf 45952 admin optional xenstore-utils_4.11.4+57-g41a822c392-2_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEcU6S3GjxzS183/1jeHlhQ1ylJm8FAl/XoasACgkQeHlhQ1yl Jm+KkA//cXCRwhJQ6nNTe206xsrcfACjIsGd+i+x1hBQfOQ0t5W6RkZdu4ZKYuQl RDRs0CCzlRgKgx5w10F+PRkS0c33xomJZQZpWTYnIBGUJEJ8IuqMq3TpuQoO12zg 5MkEtHJcsi1r27k+vojExiDFyH03iEkpiPwPYZpjiPoeFBlJNhU6rDrxJ28dS8c3 hdtuDJwsyePvMh4st/0jMKI82Vk9/FDWSFHgiUVjLyhqsHWw/5xKAI/3Y31SPe6v mHRCpsyM4JdUzlbqVP/6anf/U66lI9EIsnq7ccpMap7PbXaXDXX/IpM7NadMIybF rxXA5xtXO6LmgjZJB1U30FDsw4VA2Lp/Yh8bkLlCUWym6iy2vESxgBRk3IAjpoa6 Zw/evk3jrc/Kq412BTg9IX8yWGMl49C+1d3jrltJ3VmjYoTWI/O2OD9SURSrj9za 5Ooiyb2NMfyAyr8dwhJYmvcYE+/1h1OhDGHhN4acx9kQdHVoMdUmgv0ZbG4dD7KI QIwpd5WklHGhM/b8WqL4TuEkhGjc8VpCOIfIQz9cPj7472J0WnEeQMAx83mzO89P BPrfZmzBcFV1cin6jCSyMNhmS1cAheo4IKqPWaIjbM9VTfgF9EGBNWsdy19eH1YK 3xcTdJwapa6xFhuFFR+QRx06g85W0hmNE7mZpoh4t4N+IvPzAks= =4Ff+ -----END PGP SIGNATURE-----