Debian Package Tracker
Register | Log in
Subscribe

xen

Choose email to subscribe with

general
  • source: xen (main)
  • version: 4.20.3+127-gc42374a105-1
  • maintainer: Debian Xen Team (archive) (DMD)
  • uploaders: Hans van Kranenburg [DMD] [DM] – Ian Jackson [DMD] – Maximilian Engelhardt [DMD]
  • arch: all amd64 arm64
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.14.6-1
  • o-o-sec: 4.14.5+94-ge49571868d-1
  • oldstable: 4.17.5+72-g01140da4e8-1
  • old-sec: 4.17.7-0+deb12u1
  • stable: 4.20.2+37-g61ff35323e-0+deb13u1
  • stable-sec: 4.20.3+127-gc42374a105-0+deb13u1
  • testing: 4.20.3+127-gc42374a105-1
  • unstable: 4.20.3+127-gc42374a105-1
versioned links
  • 4.14.5+94-ge49571868d-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.14.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.17.5+72-g01140da4e8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.17.7-0+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.20.2+37-g61ff35323e-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.20.3+127-gc42374a105-0+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.20.3+127-gc42374a105-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libxen-dev
  • libxencall1
  • libxendevicemodel1
  • libxenevtchn1
  • libxenforeignmemory1
  • libxengnttab1
  • libxenhypfs1
  • libxenmisc4.20
  • libxenstore4
  • libxentoolcore1
  • libxentoollog1
  • xen-doc
  • xen-hypervisor-4.20-amd64
  • xen-hypervisor-4.20-amd64-dbg
  • xen-hypervisor-4.20-arm64
  • xen-hypervisor-4.20-arm64-dbg
  • xen-hypervisor-common (1 bugs: 0, 1, 0, 0)
  • xen-system-amd64 (1 bugs: 0, 1, 0, 0)
  • xen-system-arm64
  • xen-utils-4.20
  • xen-utils-4.20-dbg
  • xen-utils-common (3 bugs: 0, 3, 0, 0)
  • xenstore-utils
action needed
4 security issues in sid high

There are 4 open security issues in sid.

4 important issues:
  • CVE-2026-62437: When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.
  • CVE-2026-79602: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
  • CVE-2026-79603: x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.
  • CVE-2026-79604:
Created: 2026-09-08 Last update: 2026-10-05 05:00
4 security issues in forky high

There are 4 open security issues in forky.

4 important issues:
  • CVE-2026-62437: When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.
  • CVE-2026-79602: A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
  • CVE-2026-79603: x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.
  • CVE-2026-79604:
Created: 2026-09-08 Last update: 2026-10-05 05:00
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-10-05 06:00
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-10-04 Last update: 2026-10-04 00:18
lintian reports 69 warnings normal
Lintian reports 69 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-05-06 Last update: 2026-07-29 10:19
4 low-priority security issues in trixie low

There are 4 open security issues in trixie.

4 issues left for the package maintainer to handle:
  • CVE-2026-62437: (postponed; to be fixed through a stable update) When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.
  • CVE-2026-79602: (postponed; to be fixed through a stable update) A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.
  • CVE-2026-79603: (postponed; to be fixed through a stable update) x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.
  • CVE-2026-79604: (postponed; to be fixed through a stable update)

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-08 Last update: 2026-10-05 05:00
debian/patches: 20 patches to forward upstream low

Among the 20 debian patches available in version 4.20.3+127-gc42374a105-1 of the package, we noticed the following issues:

  • 20 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-07-29 12:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-07-29 06:00
news
[rss feed]
  • [2026-10-04] Accepted xen 4.17.7-0+deb12u1 (source) into oldstable-security (Hans van Kranenburg) (signed by: Sylvain Beucler)
  • [2026-08-12] Accepted xen 4.20.3+127-gc42374a105-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-08-09] Accepted xen 4.20.3+127-gc42374a105-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2026-08-03] xen 4.20.3+127-gc42374a105-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-28] Accepted xen 4.20.3+127-gc42374a105-1 (source) into unstable (Hans van Kranenburg)
  • [2026-03-06] Accepted xen 4.20.2+37-g61ff35323e-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Hans van Kranenburg)
  • [2026-02-26] xen 4.20.2+37-g61ff35323e-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-21] Accepted xen 4.20.2+37-g61ff35323e-1 (source) into unstable (Hans van Kranenburg)
  • [2025-12-20] Accepted xen 4.20.2+7-g1badcf5035-0+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-12-13] xen 4.20.2+7-g1badcf5035-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-08] Accepted xen 4.20.2+7-g1badcf5035-2 (source) into unstable (Maximilian Engelhardt) (signed by: Hans van Kranenburg)
  • [2025-12-05] Accepted xen 4.17.5+72-g01140da4e8-1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-12-02] Accepted xen 4.20.2+7-g1badcf5035-0+deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-12-02] Accepted xen 4.17.5+72-g01140da4e8-1 (source) into oldstable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-11-29] Accepted xen 4.20.2+7-g1badcf5035-1 (source) into unstable (Maximilian Engelhardt) (signed by: Hans van Kranenburg)
  • [2025-05-16] xen 4.20.0+68-g35cb38b222-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-05] Accepted xen 4.20.0+68-g35cb38b222-1 (source) into unstable (Hans van Kranenburg)
  • [2025-03-12] xen 4.20.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-07] Accepted xen 4.17.5+23-ga4e5191dc0-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Hans van Kranenburg)
  • [2025-03-06] Accepted xen 4.20.0-1 (source) into unstable (Maximilian Engelhardt) (signed by: Hans van Kranenburg)
  • [2025-02-14] Accepted xen 4.20.0~rc2+1-gfcde5e0de8-1~exp1 (all amd64 source) into experimental (Debian FTP Masters) (signed by: Sean Whitton)
  • [2025-01-27] Accepted xen 4.17.5+23-ga4e5191dc0-1 (source) into proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-01-27] xen 4.19.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-26] Accepted xen 4.17.5+23-ga4e5191dc0-1 (source) into stable-security (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2024-12-23] Accepted xen 4.19.1-1 (source) into unstable (Hans van Kranenburg)
  • [2024-12-21] Accepted xen 4.19.1-1~exp4 (amd64 source) into experimental (Debian FTP Masters) (signed by: Sean Whitton)
  • [2024-12-15] Accepted xen 4.19.1-1~exp1 (source) into experimental (Maximilian Engelhardt) (signed by: Hans van Kranenburg)
  • [2024-12-11] Accepted xen 4.19.0+14-g0918434e0f-1~exp1 (amd64 source) into experimental (Debian FTP Masters) (signed by: Sean Whitton)
  • [2024-04-26] xen 4.17.3+36-g54dacb5c02-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-11] Accepted xen 4.17.3+36-g54dacb5c02-1 (source) into unstable (Hans van Kranenburg)
  • 1
  • 2
bugs [bug history graph]
  • all: 35
  • RC: 2
  • I&N: 21
  • M&W: 12
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian (0, 69)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.20.3+127-gc42374a105-1
  • 56 bugs (6 patches)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing