-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 31 Jul 2026 23:59:26 +0200 Source: xen Architecture: source Version: 4.20.3+127-gc42374a105-0+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Debian Xen Team Changed-By: Hans van Kranenburg Closes: 1129037 Changes: xen (4.20.3+127-gc42374a105-0+deb13u1) trixie-security; urgency=medium . * Update to new upstream version 4.20.3+127-gc42374a105, which also contains security fixes for the following issues: (Closes: #1129037) - Use after free of paging structures in EPT XSA-480 CVE-2026-23554 - Xenstored DoS by unprivileged domain XSA-481 CVE-2026-23555 - oxenstored keeps quota related use counts across domain destruction XSA-483 CVE-2026-23556 - Xenstored DoS via XS_RESET_WATCHES command XSA-484 CVE-2026-23557 - grant table v2 race in status page mapping XSA-486 CVE-2026-23558 - x86: Floating Point Divider State Sampling XSA-488 CVE-2025-54505 - x86: CPU Opcode Cache corruption XSA-490 CVE-2025-54518 - x86 HVM I/O port list traversal XSA-491 CVE-2026-42487 - domctl lock open to abuse XSA-492 CVE-2026-42489 CVE-2026-42490 - Arm: Completion of memory accesses not guaranteed by completion of a TLBI XSA-493 CVE-2025-10263 - x86: mismatched mapcache metadata XSA-494 CVE-2026-42488 - x86 shadow paging is deprecated XSA-495 CVE-2026-42493 - buffer overruns in libfsimage iso9660 handling XSA-497 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 - sysctl and platform-op locks open to abuse XSA-499 CVE-2026-62426 CVE-2026-62427 - grant-table: type confusion in grant-copy XSA-500 CVE-2026-62428 - grant-table: version change racing with other operations XSA-501 CVE-2026-62435 CVE-2026-62436 - vNUMA domain cleanup may race other operations XSA-502 CVE-2026-62429 - x86: Out-of-bounds read in vRTC emulation XSA-503 CVE-2026-62430 - Viridian STIMER division by zero XSA-504 CVE-2026-62431 - evtchn: Race between FIFO expand and reset XSA-505 CVE-2026-62432 - correct buffer checks for DM_OP hypercalls XSA-506 CVE-2026-62433 - PoD: Don't try to reclaim special pages XSA-507 CVE-2026-62434 - pygrub: security-supported only when run de-privileged XSA-508 * Drop the following patches which are now included upstream: - ARM: Drop ThumbEE support - xen/arm: Set ThumbEE as not present in PFR0 * Note that the following XSA are not listed, because... - XSA-482 has patches for the Linux kernel - XSA-485 has patches for the Linux kernel - XSA-487 has patches for the Linux kernel - XSA-489 applies to XAPI which is not included in Debian - XSA-496 only applies to Xen 4.21 and later - XSA-498 applies to XAPI which is not included in Debian . xen (4.20.2+37-g61ff35323e-0+deb13u1) trixie; urgency=medium . * Update to new upstream version 4.20.2+37-g61ff35323e, which also contains security fixes for the following issues: - x86: buffer overrun with shadow paging + tracing XSA-477 CVE-2025-58150 - x86: incomplete IBPB for vCPU isolation XSA-479 CVE-2026-23553 * Note that the following XSA are not listed, because... - XSA-478 applies to XAPI which is not included in Debian Checksums-Sha1: c46cfe318ad67e955e4cd4387d6808fa65b6e485 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc db72543f43aa34ac8976c1de1a5ac1746006dc43 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz 41425edd82e9c7c6760b46905cd75b928a693ad4 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz Checksums-Sha256: d3c948203837ff192b35fc029c9755d692ba2d95fc1cb6f93a6222a381b66c48 4061 xen_4.20.3+127-gc42374a105-0+deb13u1.dsc df0831854a55a8f31cb3cb85036f2edc928e2ef098d77f815f5714bfafac68f3 4961352 xen_4.20.3+127-gc42374a105.orig.tar.xz b1f909d626f3d4ba6965ba291dd97b0dfbbe48bb8e2510913cbc1760c5e8cb3e 139540 xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz Files: b568089219efc90891347bac3b547a19 4061 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.dsc 9b708a84bd7cbcb4483cf794a3672991 4961352 admin optional xen_4.20.3+127-gc42374a105.orig.tar.xz c861bf1c0396b067c5b040d5fb164687 139540 admin optional xen_4.20.3+127-gc42374a105-0+deb13u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEESWyddwNaG9637koYssHfcmNhX2wFAmptISQACgkQssHfcmNh X2ySbhAAxBK5AgqsfROIhbTUEygRoXt8WtVQtiZ7CDODZUDBG+s4yGYben1pUoin xKQPEyFXPeehB8ipN7B3YeS/HTC+hjp9WzAG5jgO8H042h+I2E/mmpY7YhvhOky6 MiNsMgH7VfGPWItGWkyHCGgdvzEXPpLCbyqyl8cRDSc2gsEVqMpxXFGxGVZvvTfG xqJy62WJneqSoNAPY9r2kQ80DyCfQoAl+v7mkUXYMAx1POc4sBBEr/uGPqXLnTAc E916LO0dc/nFYs734BNe1pb4m7+9dP+PLxzRBzVdUBtd0M7A+/kFrZDcihgIQx+A 5QNzr05LTkjhf/vS4UrSZyDMfsQvslWTmI2/EWDlrBS3YQkx+kMCxK/Ou186IRSu 5w6Ll6Y6+T+aiHJJV1DsQcYNGciZdnS7UMm82ce9H8RDGVy0AHylEX6vnKaCIEL2 5UT7Cwxh4aPtwhqvReJ5WtXSmq/XBjqzM2K00Zdw7FuY88RFVdooIGiYNUOgHyLT XfRAUvvqXTS5wuFouwSO0Ve496EMFU4kho2nSi425jH1/Ja+kh1JJyNWOuP1C+uw STzZF0izHRPhsp7Zsuw2BioaKK7ZVWd/JBObgVT95nEI+FWWlfzKxu5M/rmH714z sb2R+fkJbJpRvR0r2jkNpaIFy6oUdy5LTbB7UxOjNu7UJU+qch8= =d/IL -----END PGP SIGNATURE-----