-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 01 Aug 2026 15:23:03 +0200
Source: xen
Architecture: source
Version: 4.17.7-0+deb12u1
Distribution: bookworm-security
Urgency: medium
Maintainer: Debian Xen Team <pkg-xen-devel@lists.alioth.debian.org>
Changed-By: Hans van Kranenburg <hans@knorrie.org>
Changes:
xen (4.17.7-0+deb12u1) bookworm-security; urgency=medium
.
* Update to new upstream version 4.17.7, which also contains
security fixes for the following issues:
- x86: buffer overrun with shadow paging + tracing
XSA-477 CVE-2025-58150
- x86: incomplete IBPB for vCPU isolation
XSA-479 CVE-2026-23553
- Use after free of paging structures in EPT
XSA-480 CVE-2026-23554
- oxenstored keeps quota related use counts across domain destruction
XSA-483 CVE-2026-23556
- Xenstored DoS via XS_RESET_WATCHES command
XSA-484 CVE-2026-23557
- grant table v2 race in status page mapping
XSA-486 CVE-2026-23558
- x86: Floating Point Divider State Sampling
XSA-488 CVE-2025-54505
- x86: CPU Opcode Cache corruption
XSA-490 CVE-2025-54518
- x86 HVM I/O port list traversal
XSA-491 CVE-2026-42487
- domctl lock open to abuse
XSA-492 CVE-2026-42489 CVE-2026-42490
- Arm: Completion of memory accesses not guaranteed by completion of a TLBI
XSA-493 CVE-2025-10263
- x86: mismatched mapcache metadata
XSA-494 CVE-2026-42488
- x86 shadow paging is deprecated
XSA-495 CVE-2026-42493
- buffer overruns in libfsimage iso9660 handling
XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425
- sysctl and platform-op locks open to abuse
XSA-499 CVE-2026-62426 CVE-2026-62427
- grant-table: type confusion in grant-copy
XSA-500 CVE-2026-62428
- grant-table: version change racing with other operations
XSA-501 CVE-2026-62435 CVE-2026-62436
- vNUMA domain cleanup may race other operations
XSA-502 CVE-2026-62429
- x86: Out-of-bounds read in vRTC emulation
XSA-503 CVE-2026-62430
- Viridian STIMER division by zero
XSA-504 CVE-2026-62431
- evtchn: Race between FIFO expand and reset
XSA-505 CVE-2026-62432
- correct buffer checks for DM_OP hypercalls
XSA-506 CVE-2026-62433
- PoD: Don't try to reclaim special pages
XSA-507 CVE-2026-62434
- pygrub: security-supported only when run de-privileged
XSA-508
* Note that the following XSA are not listed, because...
- XSA-478 applies to XAPI which is not included in Debian
- XSA-481 only applies to Xen 4.18 and later
- XSA-482 has patches for the Linux kernel
- XSA-485 has patches for the Linux kernel
- XSA-487 has patches for the Linux kernel
- XSA-489 applies to XAPI which is not included in Debian
- XSA-496 only applies to Xen 4.21 and later
- XSA-498 applies to XAPI which is not included in Debian
Checksums-Sha1:
e4ade4219435dfd8fffac76f706631750c6caf06 4284 xen_4.17.7-0+deb12u1.dsc
1dc0009de309dd26f6b6eb7cc157838f956206b3 4741296 xen_4.17.7.orig.tar.xz
d8d1bb61cdd3ff7abb442d7dddd3dcd707adf302 140360 xen_4.17.7-0+deb12u1.debian.tar.xz
017f774168e1a7d46634e61b81a5919283315e6b 5113 xen_4.17.7-0+deb12u1_source.buildinfo
Checksums-Sha256:
2ba634bac8164db6311215e064fa54d8df7ee0823ee41cc03f9c7531ddd11a4d 4284 xen_4.17.7-0+deb12u1.dsc
c0170943058d16fe7c62906b43321e32a9e3a46c3c018d3de23ead12ba1ebfc7 4741296 xen_4.17.7.orig.tar.xz
4c8a53cebc0dd1b4fa7523a04f1638cdab7bd4619f19eb6e0189d693c35dd83a 140360 xen_4.17.7-0+deb12u1.debian.tar.xz
59ba59ff35551d72f55180245f7747a8465a86b11a6108b101ad6394925fb455 5113 xen_4.17.7-0+deb12u1_source.buildinfo
Files:
890ae1e34aaa562664db89cfd8649d55 4284 admin optional xen_4.17.7-0+deb12u1.dsc
66dc9b4b8b5cd14fbbd05f2f6ae307e8 4741296 admin optional xen_4.17.7.orig.tar.xz
fee649226814b704424e5487d8397993 140360 admin optional xen_4.17.7-0+deb12u1.debian.tar.xz
5609ec19bac13cea9cd0f8c17b9e7bec 5113 admin optional xen_4.17.7-0+deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmrCpLYACgkQDTl9HeUl
XjBm3A/+IvdrH50MPuGlBvBhxBbuqU1m4Z0Nx2xe+DrTly5wLY0Xc+uC7rMaZZ/6
kU1E0BEuvt54MXYGTJTYBKzGSGaGeJ6sIHuD7ACNFhnwZ2Z/YSaYUO2mwnXQrnss
DjL+NAS1htNzoEDPAZzAgwPJPtN/wIkKfFWasOE2Ez3JVtKD6A8JqP7+JqIYxF7H
ehc1wnKndUBxNBGuFzLHv5WLqosB/+rMsx4PfZKBD379mbskgZQi5e5pnMoa98Sb
RkNZYumPiMZP51i21LPdOp6DH9F7l97i5akox4xnKOinTzZrnzQrvz1U5nI26tNt
bs1TV/C+0wHhgvJoJDIwgNG0v+CwWoHhwveX0Mzdk+jr8kmfC8VhoLhqJ92hQbOh
tdCLC6MRddOh6SjZyXis8fo5aO9hIsLD2Zf39vzsdQfYCn76Ky3eoLs1pTn34eKa
ReuhoV5F/5z6FxKyeJkxGuJZzGsBGQjhnbs1mAQito7/0xipaflLgeQGR6Cw0chY
9CuCJ5rbO953L748UEHixkoe9LiU2tzn0XapZA3rVObiL/6CimuwWCyhDlu3eob5
MdLg/eP/Un2da3NOvfRlgqwPbfzoNaDctZX56pnGND7boOOEQH1+DVUjkKPSA4mP
CMERd+ViTZBKy5Vkll0G8Af5NKfaZ0Lc2eu/lVG+0RqYjB5NWv8=
=a6yM
-----END PGP SIGNATURE-----