gmane.comp.emulators.xen.announce archive

354 archived articles, newest first (page 3 of 4). Latest articles →

Xen Security Advisory 433 v1 - x86/AMD: Zenbleed
Mon, 24 Jul 2023 16:03:45 +0000
Xen.org security team <[email protected]> • #845
Xen Security Notice 1 v1 - winpvdrvbuild.xenproject.org potentially compromised
Fri, 14 Jul 2023 17:41:00 +0000
Xen.org security team <[email protected]> • #844
Xen Security Advisory 431 v1 (CVE-2022-42336) - Mishandling of guest SSBD selection on AMD hardware
Tue, 16 May 2023 15:14:41 +0000
Xen.org security team <[email protected]> • #843
Xen Security Advisory 430 v2 (CVE-2022-42335) - x86 shadow paging arbitrary pointer dereference
Tue, 25 Apr 2023 12:02:56 +0000
Xen.org security team <[email protected]> • #842
Xen Security Advisory 427 v2 (CVE-2022-42332) - x86 shadow plus log-dirty mode use-after-free
Tue, 21 Mar 2023 12:00:39 +0000
Xen.org security team <[email protected]> • #841
Xen Security Advisory 429 v3 (CVE-2022-42331) - x86: speculative vulnerability in 32bit SYSCALL path
Tue, 21 Mar 2023 12:00:46 +0000
Xen.org security team <[email protected]> • #840
Xen Security Advisory 428 v3 (CVE-2022-42333,CVE-2022-42334) - x86/HVM pinned cache attributes mis-handling
Tue, 21 Mar 2023 12:00:43 +0000
Xen.org security team <[email protected]> • #839
Xen Security Advisory 426 v2 (CVE-2022-27672) - x86: Cross-Thread Return Address Predictions
Thu, 16 Feb 2023 17:44:49 +0000
Xen.org security team <[email protected]> • #838
Xen Security Advisory 426 v1 (CVE-2022-27672) - x86: Cross-Thread Return Address Predictions
Tue, 14 Feb 2023 18:03:16 +0000
Xen.org security team <[email protected]> • #837
Xen Security Advisory 425 v1 (CVE-2022-42330) - Guests can cause Xenstore crash via soft reset
Wed, 25 Jan 2023 14:56:39 +0000
Xen.org security team <[email protected]> • #836
[ANNOUNCEMENT] Xen 4.17 is released
Wed, 14 Dec 2022 13:07:44 +0000
Henry Wang <[email protected]> • #835
Re: Xen Security Advisory 424 v1 (CVE-2022-42328,CVE-2022-42329) - Guests can trigger deadlock in Linux netback driver
Thu, 8 Dec 2022 17:12:32 +0100
Juergen Gross <[email protected]> • #834
Xen Security Advisory 423 v2 (CVE-2022-3643) - Guests can trigger NIC interface reset/abort/crash via netback
Wed, 07 Dec 2022 15:24:25 +0000
Xen.org security team <[email protected]> • #833
Xen Security Advisory 424 v1 (CVE-2022-42328,CVE-2022-42329) - Guests can trigger deadlock in Linux netback driver
Tue, 06 Dec 2022 15:17:42 +0000
Xen.org security team <[email protected]> • #832
Xen Security Advisory 423 v1 (CVE-2022-3643) - Guests can trigger NIC interface reset/abort/crash via netback
Tue, 06 Dec 2022 15:17:32 +0000
Xen.org security team <[email protected]> • #831
Xen 4.17 rc4
Fri, 2 Dec 2022 09:33:48 +0000
Henry Wang <[email protected]> • #830
Xen 4.15.4 released
Thu, 17 Nov 2022 12:02:43 +0100
Jan Beulich <[email protected]> • #829
Xen Security Advisory 422 v2 (CVE-2022-23824) - x86: Multiple speculative security issues
Thu, 10 Nov 2022 15:24:34 +0000
Xen.org security team <[email protected]> • #828
Xen Security Advisory 422 v1 (CVE-2022-23824) - x86: Multiple speculative security issues
Tue, 08 Nov 2022 18:00:16 +0000
Xen.org security team <[email protected]> • #827
Xen 4.16.2 released
Thu, 3 Nov 2022 13:56:13 +0100
Jan Beulich <[email protected]> • #826
Xen 4.17 rc3
Thu, 3 Nov 2022 09:59:04 +0000
Henry Wang <[email protected]> • #825
Xen Security Advisory 420 v2 (CVE-2022-42324) - Oxenstored 32->31 bit integer truncation issues
Tue, 01 Nov 2022 12:00:48 +0000
Xen.org security team <[email protected]> • #824
Xen Security Advisory 421 v2 (CVE-2022-42325,CVE-2022-42326) - Xenstore: Guests can create arbitrary number of nodes via transactions
Tue, 01 Nov 2022 12:00:48 +0000
Xen.org security team <[email protected]> • #823
Xen Security Advisory 326 v4 (CVE-2022-42311,CVE-2022-42312,CVE-2022-42313,CVE-2022-42314,CVE-2022-42315,CVE-2022-42316,CVE-2022-42317,CVE-2022-42318) - Xenstore: guests can let run xenstored out of memory
Tue, 01 Nov 2022 12:00:33 +0000
Xen.org security team <[email protected]> • #822
Xen Security Advisory 419 v2 (CVE-2022-42322,CVE-2022-42323) - Xenstore: Cooperating guests can create arbitrary numbers of nodes
Tue, 01 Nov 2022 12:00:47 +0000
Xen.org security team <[email protected]> • #821
Xen Security Advisory 416 v2 (CVE-2022-42319) - Xenstore: Guests can cause Xenstore to not free temporary memory
Tue, 01 Nov 2022 12:00:45 +0000
Xen.org security team <[email protected]> • #820
Xen Security Advisory 418 v2 (CVE-2022-42321) - Xenstore: Guests can crash xenstored via exhausting the stack
Tue, 01 Nov 2022 12:00:46 +0000
Xen.org security team <[email protected]> • #819
Xen Security Advisory 414 v2 (CVE-2022-42309) - Xenstore: Guests can crash xenstored
Tue, 01 Nov 2022 12:00:43 +0000
Xen.org security team <[email protected]> • #818
Xen Security Advisory 415 v2 (CVE-2022-42310) - Xenstore: Guests can create orphaned Xenstore nodes
Tue, 01 Nov 2022 12:00:44 +0000
Xen.org security team <[email protected]> • #817
Xen Security Advisory 417 v2 (CVE-2022-42320) - Xenstore: Guests can get access to Xenstore nodes of deleted domains
Tue, 01 Nov 2022 12:00:45 +0000
Xen.org security team <[email protected]> • #816
Xen Security Advisory 412 v2 (CVE-2022-42327) - x86: unintended memory sharing between guests
Tue, 01 Nov 2022 12:00:43 +0000
Xen.org security team <[email protected]> • #815
Xen 4.17 rc2
Tue, 25 Oct 2022 01:37:10 +0000
Henry Wang <[email protected]> • #814
Xen Security Advisory 413 v2 (CVE-2022-33749) - XAPI open file limit DoS
Tue, 11 Oct 2022 12:06:11 +0000
Xen.org security team <[email protected]> • #813
Xen Security Advisory 409 v3 (CVE-2022-33747) - Arm: unbounded memory consumption for 2nd-level page tables
Tue, 11 Oct 2022 12:06:18 +0000
Xen.org security team <[email protected]> • #812
Xen Security Advisory 411 v3 (CVE-2022-33748) - lock order inversion in transitive grant copy handling
Tue, 11 Oct 2022 12:05:16 +0000
Xen.org security team <[email protected]> • #811
Xen Security Advisory 410 v3 (CVE-2022-33746) - P2M pool freeing may take excessively long
Tue, 11 Oct 2022 12:05:11 +0000
Xen.org security team <[email protected]> • #810
Xen 4.17 rc1
Sun, 9 Oct 2022 01:17:58 +0000
Henry Wang <[email protected]> • #809
Xen Security Advisory 408 v3 (CVE-2022-33745) - insufficient TLB flush for x86 PV guests in shadow mode
Tue, 26 Jul 2022 19:24:16 +0000
Xen.org security team <[email protected]> • #808
Xen Security Advisory 408 v2 (CVE-2022-33745) - insufficient TLB flush for x86 PV guests in shadow mode
Tue, 26 Jul 2022 12:44:19 +0000
Xen.org security team <[email protected]> • #807
Xen Summit Registration is now open!
Wed, 13 Jul 2022 00:27:53 +0000
George Dunlap <[email protected]> • #806
Xen Security Advisory 403 v3 (CVE-2022-26365,CVE-2022-33740,CVE-2022-33741,CVE-2022-33742) - Linux disk/nic frontends data leaks
Tue, 05 Jul 2022 12:04:14 +0000
Xen.org security team <[email protected]> • #805
Xen Security Advisory 406 v3 (CVE-2022-33744) - Arm guests can cause Dom0 DoS via PV devices
Tue, 05 Jul 2022 12:04:23 +0000
Xen.org security team <[email protected]> • #804
Xen Security Advisory 405 v3 (CVE-2022-33743) - network backend may cause Linux netfront to use freed SKBs
Tue, 05 Jul 2022 12:04:18 +0000
Xen.org security team <[email protected]> • #803
Xen 4.15.3 released
Mon, 4 Jul 2022 14:28:41 +0200
Jan Beulich <[email protected]> • #802
Xen Security Advisory 404 v2 (CVE-2022-21123,CVE-2022-21125,CVE-2022-21166) - x86: MMIO Stale Data vulnerabilities
Thu, 16 Jun 2022 16:10:02 +0000
Xen.org security team <[email protected]> • #801
XenSummit 2022 Call for Papers open
Wed, 15 Jun 2022 10:25:34 +0000
George Dunlap <[email protected]> • #800
Xen Security Advisory 404 v1 (CVE-2022-21123,CVE-2022-21124,CVE-2022-21166) - x86: MMIO Stale Data vulnerabilities
Tue, 14 Jun 2022 18:26:37 +0000
Xen.org security team <[email protected]> • #799
Xen Security Advisory 402 v4 (CVE-2022-26363,CVE-2022-26364) - x86 pv: Insufficient care with non-coherent mappings
Thu, 09 Jun 2022 12:08:26 +0000
Xen.org security team <[email protected]> • #798
Xen Security Advisory 401 v2 (CVE-2022-26362) - x86 pv: Race condition in typeref acquisition
Thu, 09 Jun 2022 12:07:54 +0000
Xen.org security team <[email protected]> • #797
Xen 4.14.5 released
Thu, 14 Apr 2022 16:20:21 +0200
Jan Beulich <[email protected]> • #796
Xen 4.16.1 released
Thu, 14 Apr 2022 16:18:51 +0200
Jan Beulich <[email protected]> • #795
Xen Security Advisory 400 v2 (CVE-2022-26358,CVE-2022-26359,CVE-2022-26360,CVE-2022-26361) - IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues
Tue, 05 Apr 2022 12:03:18 +0000
Xen.org security team <[email protected]> • #794
Xen Security Advisory 397 v2 (CVE-2022-26356) - Racy interactions between dirty vram tracking and paging log dirty hypercalls
Tue, 05 Apr 2022 12:00:24 +0000
Xen.org security team <[email protected]> • #793
Xen Security Advisory 399 v2 (CVE-2022-26357) - race in VT-d domain ID cleanup
Tue, 05 Apr 2022 12:00:29 +0000
Xen.org security team <[email protected]> • #792
Xen Security Advisory 398 v2 - Multiple speculative security issues
Fri, 18 Mar 2022 15:07:33 +0000
Xen.org security team <[email protected]> • #791
Xen Security Advisory 396 v3 (CVE-2022-23036,CVE-2022-23037,CVE-2022-23038,CVE-2022-23039,CVE-2022-23040,CVE-2022-23041,CVE-2022-23042) - Linux PV device frontends vulnerable to attacks by backends
Thu, 10 Mar 2022 12:00:25 +0000
Xen.org security team <[email protected]> • #790
Xen Security Advisory 398 v1 - Multiple speculative security issues
Tue, 08 Mar 2022 18:16:43 +0000
Xen.org security team <[email protected]> • #789
Xen 4.14.4 released
Thu, 3 Feb 2022 15:15:26 +0100
Jan Beulich <[email protected]> • #788
Xen 4.15.2 released
Thu, 3 Feb 2022 15:13:51 +0100
Jan Beulich <[email protected]> • #787
Xen Security Advisory 395 v2 (CVE-2022-23035) - Insufficient cleanup of passed-through device IRQs
Tue, 25 Jan 2022 12:05:07 +0000
Xen.org security team <[email protected]> • #786
Xen Security Advisory 393 v2 (CVE-2022-23033) - arm: guest_physmap_remove_page not removing the p2m mappings
Tue, 25 Jan 2022 12:04:34 +0000
Xen.org security team <[email protected]> • #785
Xen Security Advisory 394 v3 (CVE-2022-23034) - A PV guest could DoS Xen while unmapping a grant
Tue, 25 Jan 2022 12:05:03 +0000
Xen.org security team <[email protected]> • #784
Xen Security Advisory 376 v1 - frontends vulnerable to backends
Mon, 20 Dec 2021 12:04:21 +0000
Xen.org security team <[email protected]> • #783
Xen Security Advisory 391 v3 (CVE-2021-28711,CVE-2021-28712,CVE-2021-28713) - Rogue backends can cause DoS of guests via high frequency events
Mon, 20 Dec 2021 12:02:50 +0000
Xen.org security team <[email protected]> • #782
Xen Security Advisory 392 v4 (CVE-2021-28714,CVE-2021-28715) - Guest can force Linux netback driver to hog large amounts of kernel memory
Mon, 20 Dec 2021 12:03:09 +0000
Xen.org security team <[email protected]> • #781
Re: Xen 4.16 is released
Thu, 2 Dec 2021 15:19:44 +0000
Ian Jackson <[email protected]> • #780
Xen 4.16 is released
Thu, 2 Dec 2021 14:40:55 +0000
Ian Jackson <[email protected]> • #779
Xen 4.16 RC4
Tue, 23 Nov 2021 16:21:29 +0000
Ian Jackson <[email protected]> • #778
Xen Security Advisory 385 v2 (CVE-2021-28706) - guests may exceed their designated memory limit
Tue, 23 Nov 2021 12:11:12 +0000
Xen.org security team <[email protected]> • #777
Xen Security Advisory 389 v3 (CVE-2021-28705,CVE-2021-28709) - issues with partially successful P2M updates on x86
Tue, 23 Nov 2021 12:11:14 +0000
Xen.org security team <[email protected]> • #776
Xen Security Advisory 388 v3 (CVE-2021-28704,CVE-2021-28707,CVE-2021-28708) - PoD operations on misaligned GFNs
Tue, 23 Nov 2021 12:11:13 +0000
Xen.org security team <[email protected]> • #775
Xen Security Advisory 387 v2 (CVE-2021-28703) - grant table v2 status pages may remain accessible after de-allocation (take two)
Tue, 23 Nov 2021 12:11:36 +0000
Xen.org security team <[email protected]> • #774
Xen Security Advisory 390 v1 (CVE-2021-28710) - certain VT-d IOMMUs may not work in shared page table mode
Fri, 19 Nov 2021 14:10:54 +0000
Xen.org security team <[email protected]> • #773
Xen 4.16 RC3
Tue, 16 Nov 2021 17:39:58 +0000
Ian Jackson <[email protected]> • #772
Xen 4.16 RC2
Mon, 8 Nov 2021 18:03:00 +0000
Ian Jackson <[email protected]> • #771
Xen 4.16 RC1
Mon, 1 Nov 2021 12:59:15 +0000
Ian Jackson <[email protected]> • #770
Xen Security Advisory 386 v2 (CVE-2021-28702) - PCI devices with RMRRs not deassigned correctly
Thu, 07 Oct 2021 14:41:16 +0000
Xen.org security team <[email protected]> • #769
Xen Security Advisory 386 v1 (CVE-2021-28702) - PCI devices with RMRRs not deassigned correctly
Tue, 05 Oct 2021 18:43:10 +0000
Xen.org security team <[email protected]> • #768
Xen 4.16 development update; request for regression bug reports
Mon, 27 Sep 2021 15:24:27 +0100
Ian Jackson <[email protected]> • #767
Xen Security Advisory 378 v3 (CVE-2021-28694,CVE-2021-28695,CVE-2021-28696) - IOMMU page mapping issues on x86
Wed, 01 Sep 2021 09:30:46 +0000
Xen.org security team <[email protected]> • #766
Xen Security Advisory 378 v2 (CVE-2021-28694,CVE-2021-28695,CVE-2021-28696) - IOMMU page mapping issues on x86
Wed, 25 Aug 2021 12:01:32 +0000
Xen.org security team <[email protected]> • #765
Xen 4.14.3 released
Mon, 13 Sep 2021 13:02:17 +0200
Jan Beulich <[email protected]> • #764
Xen 4.15.1 released
Fri, 10 Sep 2021 15:26:17 +0200
Jan Beulich <[email protected]> • #763
Xen 4.13.4 released
Fri, 10 Sep 2021 15:25:06 +0200
Jan Beulich <[email protected]> • #762
Xen Security Advisory 384 v3 (CVE-2021-28701) - Another race in XENMAPSPACE_grant_table handling
Wed, 08 Sep 2021 12:28:17 +0000
Xen.org security team <[email protected]> • #761
Xen Security Advisory 380 v3 (CVE-2021-28698) - long running loops in grant table handling
Wed, 01 Sep 2021 09:30:50 +0000
Xen.org security team <[email protected]> • #760
Xen Security Advisory 382 v2 (CVE-2021-28699) - inadequate grant-v2 status frames array bounds check
Wed, 25 Aug 2021 12:01:35 +0000
Xen.org security team <[email protected]> • #759
Xen Security Advisory 380 v2 (CVE-2021-28698) - long running loops in grant table handling
Wed, 25 Aug 2021 12:01:34 +0000
Xen.org security team <[email protected]> • #758
Xen Security Advisory 383 v2 (CVE-2021-28700) - xen/arm: No memory limit for dom0less domUs
Wed, 25 Aug 2021 12:01:36 +0000
Xen.org security team <[email protected]> • #757
Xen Security Advisory 379 v2 (CVE-2021-28697) - grant table v2 status pages may remain accessible after de-allocation
Wed, 25 Aug 2021 12:01:33 +0000
Xen.org security team <[email protected]> • #756
Xen Security Advisory 375 v4 (CVE-2021-0089,CVE-2021-26313) - Speculative Code Store Bypass
Thu, 10 Jun 2021 09:16:42 +0000
Xen.org security team <[email protected]> • #755
Xen Security Advisory 375 v3 (CVE-2021-0089,CVE-2021-26313) - Speculative Code Store Bypass
Wed, 09 Jun 2021 13:50:38 +0000
Xen.org security team <[email protected]> • #754
Xen Security Advisory 375 v2 (CVE-2021-0089) - Speculative Code Store Bypass
Tue, 08 Jun 2021 17:04:30 +0000
Xen.org security team <[email protected]> • #753
Xen Security Advisory 372 v3 (CVE-2021-28693) - xen/arm: Boot modules are not scrubbed
Tue, 08 Jun 2021 17:04:28 +0000
Xen.org security team <[email protected]> • #752
Xen Security Advisory 374 v2 (CVE-2021-28691) - Guest triggered use-after-free in Linux xen-netback
Tue, 08 Jun 2021 17:04:30 +0000
Xen.org security team <[email protected]> • #751
Xen Security Advisory 373 v2 (CVE-2021-28692) - inappropriate x86 IOMMU timeout detection / handling
Tue, 08 Jun 2021 17:04:29 +0000
Xen.org security team <[email protected]> • #750
Xen Security Advisory 377 v2 (CVE-2021-28690) - x86: TSX Async Abort protections not restored after S3
Tue, 08 Jun 2021 17:04:31 +0000
Xen.org security team <[email protected]> • #749
Xen Security Advisory 370 v2 (CVE-2021-28689) - x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests
Tue, 04 May 2021 12:02:06 +0000
Xen.org security team <[email protected]> • #748
Xen 4.14.2 released
Fri, 30 Apr 2021 08:51:56 +0200
Jan Beulich <[email protected]> • #747
XenSummit Design sessions website open for submissions
Tue, 27 Apr 2021 13:15:14 +0000
George Dunlap <[email protected]> • #746
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.