GLSA 202402-07: Xen: Multiple Vulnerabilities
Severity: | high |
Title: | Xen: Multiple Vulnerabilities |
Date: | 02/04/2024 |
Bugs: |
|
ID: | 202402-07 |
Synopsis
Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.Background
Xen is a bare-metal hypervisor.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
app-emulation/xen | < 4.16.6_pre1 | >= 4.16.6_pre1 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in Xen. Please review the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Xen users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.16.6_pre1"
References
XSA-430 XSA-425 XSA-422 XSA-421 XSA-420 XSA-419 XSA-418 XSA-417 XSA-416 XSA-415 XSA-414 XSA-412 XSA-407 XSA-400 XSA-399 XSA-397 XSA-389 XSA-388 XSA-387 XSA-385 XSA-355 XSA-351 CVE-2022-42335 CVE-2022-42334 CVE-2022-42333 CVE-2022-42332 CVE-2022-42331 CVE-2022-42330 CVE-2022-42327 CVE-2022-42326 CVE-2022-42325 CVE-2022-42324 CVE-2022-42323 CVE-2022-42322 CVE-2022-42321 CVE-2022-42320 CVE-2022-42319 CVE-2022-42310 CVE-2022-42309 CVE-2022-33749 CVE-2022-33748 CVE-2022-33747 CVE-2022-33746 CVE-2022-29901 CVE-2022-29900 CVE-2022-27672 CVE-2022-26361 CVE-2022-26360 CVE-2022-26359 CVE-2022-26358 CVE-2022-26357 CVE-2022-26356 CVE-2022-23825 CVE-2022-23824 CVE-2022-23816 CVE-2021-28709 CVE-2021-28708 CVE-2021-28707 CVE-2021-28706 CVE-2021-28705 CVE-2021-28704 CVE-2021-28703
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.