-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 12 Oct 2023 19:25:55 +0200 Source: xen Architecture: source Version: 4.17.2+55-g0b56bed864-1 Distribution: unstable Urgency: medium Maintainer: Debian Xen Team <pkg-xen-devel@lists.alioth.debian.org> Changed-By: Hans van Kranenburg <hans@knorrie.org> Changes: xen (4.17.2+55-g0b56bed864-1) unstable; urgency=medium . * Update to new upstream version 4.17.2+55-g0b56bed864, which also contains security fixes for the following issues: - arm32: The cache may not be properly cleaned/invalidated XSA-437 CVE-2023-34321 - top-level shadow reference dropped too early for 64-bit PV guests XSA-438 CVE-2023-34322 - x86/AMD: Divide speculative information leak XSA-439 CVE-2023-20588 - xenstored: A transaction conflict can crash C Xenstored XSA-440 CVE-2023-34323 - x86/AMD: missing IOMMU TLB flushing XSA-442 CVE-2023-34326 - Multiple vulnerabilities in libfsimage disk handling XSA-443 CVE-2023-34325 - x86/AMD: Debug Mask handling XSA-444 CVE-2023-34327 CVE-2023-34328 * Note that the following XSA are not listed, because... - XSA-441 has patches for the Linux kernel. Checksums-Sha1: 06179e5b2504921d001c20e0481500eb31bbede9 4482 xen_4.17.2+55-g0b56bed864-1.dsc a879b081b311cbe3bfc60d17a8d0a1eb71659354 4668608 xen_4.17.2+55-g0b56bed864.orig.tar.xz 0caca2e6d0e60ffe68d00a528d94edf78bfbafba 136688 xen_4.17.2+55-g0b56bed864-1.debian.tar.xz Checksums-Sha256: 1e94ca080c34a53ccd75e6235637c519e4a9f5919824cd4c5bb383616b6e3770 4482 xen_4.17.2+55-g0b56bed864-1.dsc 799dc5a6ecba78c585560616e9da7b5b8c304eaaee3a25f44513faa369813ff0 4668608 xen_4.17.2+55-g0b56bed864.orig.tar.xz 4991760b4d86db5416d8d2d474511005b211385c19d597abb927fbec67c0d483 136688 xen_4.17.2+55-g0b56bed864-1.debian.tar.xz Files: 10e92d8a6aec1a2fd62a043e2e403482 4482 admin optional xen_4.17.2+55-g0b56bed864-1.dsc 88408792ef3af4415713e61f26126b3a 4668608 admin optional xen_4.17.2+55-g0b56bed864.orig.tar.xz 9d74d8f475f8d4c90e78a01aa56abd16 136688 admin optional xen_4.17.2+55-g0b56bed864-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEESWyddwNaG9637koYssHfcmNhX2wFAmUpq38ACgkQssHfcmNh X2xyIxAAmPOIGiK0CmcdD9D4fab5QUoeaZ9XaEmv3fQfqT1N66qIdYfrxYi04TQu YFjgNscI2294NIkxTurR+pYR1pLICXqnRmpoKOfBMpQtoLW8xDDNv68SERz/qHf+ SM05AF7rp1dPH2cDXu2wBEq+IDKbtEdL7OXcUWFQv84bPCNlI6mBzHwQ9wNLNsrS VoBmRB+N1UJftKGt5PQs8eXmf+hukGEQdB4gbBsETiGqSQFPMR6Og27r3PCRPWFb yjgBsiFwlWX2khftrBuA3LD5dSEbi3N58sgxPogDqtHt1ThhADnbJEnJCVvPP/84 nkhtdZeOW9PUqHfRJ8riGAIsfFyFZLAfgYfo5idgos6IqcOOfWMEy3oonp3KHTyd UDMAmVO+rIRfxpmFBd8z4h3FFQ39bDcREgfr9wQmpma3fYUduStZqIkKJ/TPggHX 7btjEOW1sDEEheffQN/7u17J75gTBfd/Ton4JAKZy5o3D0paZfNfpG2AznBS0drj Ef7gT4Wb/d6RaCo/GK4dUrQUYuVsIj59wp+pVt92XZaJOJBJRF4cbn/yFnaXKYxC 1m6pNyz9Vv4+JTHN2aHG+dBNaFgZAB72o9YOfWVMXdsg/AuLERy+QJfcefT4ztT3 siDhUZckKnnGD0uGdBAtU6/KFYUeUNaMAM9XUEqMg1+gtAr0Hj4= =+oXY -----END PGP SIGNATURE-----