Fedora Linux 8565 Published by

A xen security update has been released for Fedora 33.



SECURITY: Fedora 33 Update: xen-4.14.1-5.fc33


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-47f53a940a
2021-02-26 01:07:35.019046
--------------------------------------------------------------------------------

Name : xen
Product : Fedora 33
Version : 4.14.1
Release : 5.fc33
URL :   http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

Linux: display frontend "be-alloc" mode is unsupported (comment only) [XSA-363,
CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated
scrubbed pages [XSA-364, CVE-2021-26933] (#1929547)
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb 16 2021 Michael Young - 4.14.1-5
- Linux: display frontend "be-alloc" mode is unsupported (comment only)
[XSA-363, CVE-2021-26934]
- arm: The cache may not be cleaned for newly allocated scrubbed pages
[XSA-364, CVE-2021-26933]
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1929546 - CVE-2021-26933 xen: arm: The cache may not be cleaned for newly allocated scrubbed pages
  https://bugzilla.redhat.com/show_bug.cgi?id=1929546
[ 2 ] Bug #1929548 - CVE-2021-26934 xen: Linux: display frontend "be-alloc" mode is unsupported
  https://bugzilla.redhat.com/show_bug.cgi?id=1929548
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-47f53a940a' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys