File _patchinfo of Package patchinfo.17647
<patchinfo incident="17647">
<issue tracker="bnc" id="1179501">VUL-0: EMBARGOED: CVE-2020-29484: xen: xenstore: guests can crash xenstored via watchs (XSA-324 v2)</issue>
<issue tracker="bnc" id="1027519">Xen: Missing upstream bug fixes</issue>
<issue tracker="bnc" id="1179496">VUL-0: EMBARGOED: CVE-2020-29480: xen: xenstore: watch notifications lacking permission checks (XSA-115 v3)</issue>
<issue tracker="bnc" id="1179514">VUL-0: EMBARGOED: CVE-2020-29570: xen: FIFO event channels control block related ordering (XSA-358 v3)</issue>
<issue tracker="bnc" id="1179506">VUL-0: EMBARGOED: CVE-2020-29566: xen: undue recursion in x86 HVM context switch code (XSA-348 v2)</issue>
<issue tracker="bnc" id="1179498">VUL-0: EMBARGOED: CVE-2020-29481: xen: xenstore: new domains inheriting existing node permissions (XSA-322 v3)</issue>
<issue tracker="bnc" id="1179516">VUL-0: EMBARGOED: CVE-2020-29571: xen: FIFO event channels control structure ordering (XSA-359 v2)</issue>
<issue tracker="bnc" id="1179502">VUL-0: EMBARGOED: CVE-2020-29483: xen: xenstore: guests can disturb domain cleanup (XSA-325 v2)</issue>
<issue tracker="bnc" id="1176782">L3: xl dump-core shows missing nr_pages during core. If maxmem and current are the same the issue doesn't happen</issue>
<issue tracker="cve" id="2020-29571"/>
<issue tracker="cve" id="2020-29484"/>
<issue tracker="cve" id="2020-29480"/>
<issue tracker="cve" id="2020-29483"/>
<issue tracker="cve" id="2020-29570"/>
<issue tracker="cve" id="2020-29566"/>
<issue tracker="cve" id="2020-29481"/>
<packager>charlesa</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for xen</summary>
<description>This update for xen fixes the following issues:
- CVE-2020-29480: Fixed an issue which could have allowed leak of non-sensitive data to administrator guests (bsc#117949 XSA-115).
- CVE-2020-29481: Fixed an issue which could have allowd to new domains to inherit existing node permissions (bsc#1179498 XSA-322).
- CVE-2020-29483: Fixed an issue where guests could disturb domain cleanup (bsc#1179502 XSA-325).
- CVE-2020-29484: Fixed an issue where guests could crash xenstored via watchs (bsc#1179501 XSA-324).
- CVE-2020-29566: Fixed an undue recursion in x86 HVM context switch code (bsc#1179506 XSA-348).
- CVE-2020-29570: Fixed an issue where FIFO event channels control block related ordering (bsc#1179514 XSA-358).
- CVE-2020-29571: Fixed an issue where FIFO event channels control structure ordering (bsc#1179516 XSA-359).
- Fixed an issue where dump-core shows missing nr_pages during core (bsc#1176782).
- Multiple other bugs (bsc#1027519)
</description>
</patchinfo>