-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 31 Jul 2026 23:59:26 +0200 Source: xen Architecture: source Version: 4.20.3+127-gc42374a105-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian Xen Team <pkg-xen-devel@lists.alioth.debian.org> Changed-By: Hans van Kranenburg <hans@knorrie.org> Closes: 1129037 Changes: xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=medium . * Update to new upstream version 4.20.3+127-gc42374a105, which also contains security fixes for the following issues: (Closes: #1129037) - Use after free of paging structures in EPT XSA-480 CVE-2026-23554 - Xenstored DoS by unprivileged domain XSA-481 CVE-2026-23555 - oxenstored keeps quota related use counts across domain destruction XSA-483 CVE-2026-23556 - Xenstored DoS via XS_RESET_WATCHES command XSA-484 CVE-2026-23557 - grant table v2 race in status page mapping XSA-486 CVE-2026-23558 - x86: Floating Point Divider State Sampling XSA-488 CVE-2025-54505 - x86: CPU Opcode Cache corruption XSA-490 CVE-2025-54518 - x86 HVM I/O port list traversal XSA-491 CVE-2026-42487 - domctl lock open to abuse XSA-492 CVE-2026-42489 CVE-2026-42490 - Arm: Completion of memory accesses not guaranteed by completion of a TLBI XSA-493 CVE-2025-10263 - x86: mismatched mapcache metadata XSA-494 CVE-2026-42488 - x86 shadow paging is deprecated XSA-495 CVE-2026-42493 - buffer overruns in libfsimage iso9660 handling XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 - sysctl and platform-op locks open to abuse XSA-499 CVE-2026-62426 CVE-2026-62427 - grant-table: type confusion in grant-copy XSA-500 CVE-2026-62428 - grant-table: version change racing with other operations XSA-501 CVE-2026-62435 CVE-2026-62436 - vNUMA domain cleanup may race other operations XSA-502 CVE-2026-62429 - x86: Out-of-bounds read in vRTC emulation XSA-503 CVE-2026-62430 - Viridian STIMER division by zero XSA-504 CVE-2026-62431 - evtchn: Race between FIFO expand and reset XSA-505 CVE-2026-62432 - correct buffer checks for DM_OP hypercalls XSA-506 CVE-2026-62433 - PoD: Don't try to reclaim special pages XSA-507 CVE-2026-62434 - pygrub: security-supported only when run de-privileged XSA-508 * Drop the following patches which are now included upstream: - ARM: Drop ThumbEE support - xen/arm: Set ThumbEE as not present in PFR0 * Note that the following XSA are not listed, because... - XSA-482 has patches for the Linux kernel - XSA-485 has patches for the Linux kernel - XSA-487 has patches for the Linux kernel - XSA-489 applies to XAPI which is not included in Debian - XSA-496 only applies to Xen 4.21 and later - XSA-498 applies to XAPI which is not included in Debian . xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=medium . * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains security fixes for the following issues: - x86: buffer overrun with shadow paging + tracing XSA-477 CVE-2025-58150 - x86: incomplete IBPB for vCPU isolation XSA-479 CVE-2026-23553 * Note that the following XSA are not listed, because... - XSA-478 applies to XAPI which is not included in Debian Checksums-Sha1: dbefdd4e57cb83580029c043e5ed8abe21d8fd1c 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz 41425edd82e9c7c6760b46905cd75b928a693ad4 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz Checksums-Sha256: 659b0858c1559ed7203c09d2eeb6091e50735b78079158ec7e94de573528d6f7 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz b1f909d626f3d4ba6965ba291dd97b0dfbbe48bb8e2510913cbc1760c5e8cb3e 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz Files: ce25ea9a9a2d953006437dee63b6a04f 4061 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.dsc 9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc42374a105.orig.tar.xz c861bf1c0396b067c5b040d5fb164687 139540 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp3DGAACgkQEMKTtsN8 TjamrxAAwEQ5GT89wPUseyBqvX5nwlu2w41jzRHHJTpPb/y1kDagOyW5iFfZLWL/ FxEYjb7BzjLCNsUVVlfUi/H0NMeFzkWwMbik7obcUvxMULHVYl8LBUAK0h+MD5WS yTPwy4kh3Mih8vfZ9YFIr9bBcOfB7wnz8ADfxsQRBqIZoyjKVcA3nVG3pjZeUKsR bdwOD8FzHqK6UVYS97tRfJgMqWpAHLI/AshUIn+iy5g0FmSmt3JeJQsw2klFOCAd 589KObPF2nIGgeokFJ8Xotyk9JMXOxor6yzCuMMjjJAHSaq7qC6hvj/lXNkL8ErN tKdScOZtDHyH5sXS39fAxH+oVv7p0BJvO1EfOiSeY47ckRc42KQmDNGVrOzCP+E8 yUCi58pwQaHT4AiQNhTD8AY4sGbAEMOCIwOarz3aVLKNXEz+zqh3CXY4NFO3waEI TvEfH8K2j06KJNkg7vWcoRugZ574w7TdIVYuqHLvnFgR7dLZBiyaRL/0qyqWrkvl NvnIqtuc8G6UwNt6DMXzqwVVBsy/tSdTJlwOhh2ew1F49DuLkDHYuFvudm38qmgH zXCGbcRDtbly1k9U7ogLGm2zoeOVu5CXN9ONmkan+JrR3ozhQeWDh+CJlIIqkAwN LAzSXpmpY5H2zxnmTvyuOxBegYVZBVLYxo7wj8+OblVVE//Y3KY= =wGHr -----END PGP SIGNATURE-----