Fedora Linux 8567 Published by

A xen security update has been released for Fedora 36.



SECURITY: Fedora 36 Update: xen-4.16.2-2.fc36


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-5b594b82ac
2022-10-30 20:59:07.278645
--------------------------------------------------------------------------------

Name : xen
Product : Fedora 36
Version : 4.16.2
Release : 2.fc36
URL :   http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

Arm: unbounded memory consumption for 2nd-level page tables [XSA-409,
CVE-2022-33747] P2M pool freeing may take excessively long [XSA-410,
CVE-2022-33746] lock order inversion in transitive grant copy handling [XSA-411,
CVE-2022-33748]
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 14 2022 Michael Young - 4.16.2-2
- Arm: unbounded memory consumption for 2nd-level page tables [XSA-409,
CVE-2022-33747]
- P2M pool freeing may take excessively long [XSA-410, CVE-2022-33746]
- lock order inversion in transitive grant copy handling [XSA-411,
CVE-2022-33748]
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2135262 - CVE-2022-33748 xen: lock order inversion in transitive grant copy handling
  https://bugzilla.redhat.com/show_bug.cgi?id=2135262
[ 2 ] Bug #2135267 - CVE-2022-33747 xen: unbounded memory consumption for 2nd-level page tables
  https://bugzilla.redhat.com/show_bug.cgi?id=2135267
[ 3 ] Bug #2135640 - CVE-2022-33746 xen: P2M pool freeing may take excessively long
  https://bugzilla.redhat.com/show_bug.cgi?id=2135640
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-5b594b82ac' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________