-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 15:23:03 +0200 Source: xen Architecture: source Version: 4.17.7-0+deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: Debian Xen Team Changed-By: Hans van Kranenburg Changes: xen (4.17.7-0+deb12u1) bookworm-security; urgency=medium . * Update to new upstream version 4.17.7, which also contains security fixes for the following issues: - x86: buffer overrun with shadow paging + tracing XSA-477 CVE-2025-58150 - x86: incomplete IBPB for vCPU isolation XSA-479 CVE-2026-23553 - Use after free of paging structures in EPT XSA-480 CVE-2026-23554 - oxenstored keeps quota related use counts across domain destruction XSA-483 CVE-2026-23556 - Xenstored DoS via XS_RESET_WATCHES command XSA-484 CVE-2026-23557 - grant table v2 race in status page mapping XSA-486 CVE-2026-23558 - x86: Floating Point Divider State Sampling XSA-488 CVE-2025-54505 - x86: CPU Opcode Cache corruption XSA-490 CVE-2025-54518 - x86 HVM I/O port list traversal XSA-491 CVE-2026-42487 - domctl lock open to abuse XSA-492 CVE-2026-42489 CVE-2026-42490 - Arm: Completion of memory accesses not guaranteed by completion of a TLBI XSA-493 CVE-2025-10263 - x86: mismatched mapcache metadata XSA-494 CVE-2026-42488 - x86 shadow paging is deprecated XSA-495 CVE-2026-42493 - buffer overruns in libfsimage iso9660 handling XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 - sysctl and platform-op locks open to abuse XSA-499 CVE-2026-62426 CVE-2026-62427 - grant-table: type confusion in grant-copy XSA-500 CVE-2026-62428 - grant-table: version change racing with other operations XSA-501 CVE-2026-62435 CVE-2026-62436 - vNUMA domain cleanup may race other operations XSA-502 CVE-2026-62429 - x86: Out-of-bounds read in vRTC emulation XSA-503 CVE-2026-62430 - Viridian STIMER division by zero XSA-504 CVE-2026-62431 - evtchn: Race between FIFO expand and reset XSA-505 CVE-2026-62432 - correct buffer checks for DM_OP hypercalls XSA-506 CVE-2026-62433 - PoD: Don't try to reclaim special pages XSA-507 CVE-2026-62434 - pygrub: security-supported only when run de-privileged XSA-508 * Note that the following XSA are not listed, because... - XSA-478 applies to XAPI which is not included in Debian - XSA-481 only applies to Xen 4.18 and later - XSA-482 has patches for the Linux kernel - XSA-485 has patches for the Linux kernel - XSA-487 has patches for the Linux kernel - XSA-489 applies to XAPI which is not included in Debian - XSA-496 only applies to Xen 4.21 and later - XSA-498 applies to XAPI which is not included in Debian Checksums-Sha1: 427d59e796948630e06c0dda96e8cbba7203885b 4284 xen_4.17.7-0+deb12u1.dsc 1dc0009de309dd26f6b6eb7cc157838f956206b3 4741296 xen_4.17.7.orig.tar.xz f91286d27a6369b8a1182c3c5aa2066f014709c0 140472 xen_4.17.7-0+deb12u1.debian.tar.xz Checksums-Sha256: 16a2596eed13fb297b807959c145e8877345ab907c3d6dcab51ea966205f2d2c 4284 xen_4.17.7-0+deb12u1.dsc c0170943058d16fe7c62906b43321e32a9e3a46c3c018d3de23ead12ba1ebfc7 4741296 xen_4.17.7.orig.tar.xz 251a166eb40b789f1128b21213e2a38d84ad3e72050a048bbb6d199cf371b53f 140472 xen_4.17.7-0+deb12u1.debian.tar.xz Files: 764cd8f911d95935848f2cda2e311ff3 4284 admin optional xen_4.17.7-0+deb12u1.dsc 66dc9b4b8b5cd14fbbd05f2f6ae307e8 4741296 admin optional xen_4.17.7.orig.tar.xz 78b75b7844dfcfbf13cc8815fcdf298d 140472 admin optional xen_4.17.7-0+deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEESWyddwNaG9637koYssHfcmNhX2wFAmpt87EACgkQssHfcmNh X2xFlRAAq6nBeB3YCbzdW9LR77UgVZv/1RrE9ZD2XFBqV0XVXyA5G65DCj6VHSJU WRftgcbDEPZlTR8ItADe11T+dkuhhbOCOcbrHJPEtMJ9IsQ6A5wUGwNF4Y+EUx7B fJlP5EUemoxzFUWq0BC0hBQJqeje+edEu8FTt0LixelKYxnRnlPlnGgzyV6bnQ8P 53BqYkLDKQcCuXpMWJaPZ6jY/kyRe8dapy+uS1H6JCg2uWIM29wWR8EG3nx4WVJS 7nPOehQYmeHn8NDZMIJKHHYRMMarLu+XqgEJJ9zkltq9uydccVDht2RTyi7OWWmn 0Ma/u/VWb11BcmO8i+o3kMEuYi6u7mVnh4fghPmRIPeyMqUtd5dtySPiqyO8ZZJ9 1w2sGk7WELBQRaZob1DyBEWH4UIvfznHmuSkwCICDBv4O9A6qdHY2FoVMx3y+/4M WmR4dk2UXVMtiwCf+edE50CgqS3SaMzpzgsI/rk7TuP6nQs5Ia0lO/YbPWz1HlOD VPWggREo+j/wVPaynCFrUGGtAgzGJI2vQ4jvhaK/o/uuu1/Zof2aayvVULNJ8BeC PQTYcb4+ymhayrWnvlIVtt78FSCfwQP+lZE1U7KZMXuSEesaR4wV1TNxDusqwkkw XrSvbFm5DfI4jZfs3X//a3cUYdKgWeKUdxkzyU/O2UEU398jKNI= =i3MM -----END PGP SIGNATURE-----