File _patchinfo of Package patchinfo.17645
<patchinfo incident="17645"> <issue tracker="bnc" id="1179498">VUL-0: EMBARGOED: CVE-2020-29481: xen: xenstore: new domains inheriting existing node permissions (XSA-322 v3)</issue> <issue tracker="bnc" id="1179516">VUL-0: EMBARGOED: CVE-2020-29571: xen: FIFO event channels control structure ordering (XSA-359 v2)</issue> <issue tracker="bnc" id="1179514">VUL-0: EMBARGOED: CVE-2020-29570: xen: FIFO event channels control block related ordering (XSA-358 v3)</issue> <issue tracker="bnc" id="1176782">L3: xl dump-core shows missing nr_pages during core. If maxmem and current are the same the issue doesn't happen</issue> <issue tracker="bnc" id="1179502">VUL-0: EMBARGOED: CVE-2020-29483: xen: xenstore: guests can disturb domain cleanup (XSA-325 v2)</issue> <issue tracker="bnc" id="1179501">VUL-0: EMBARGOED: CVE-2020-29484: xen: xenstore: guests can crash xenstored via watchs (XSA-324 v2)</issue> <issue tracker="bnc" id="1179496">VUL-0: EMBARGOED: CVE-2020-29480: xen: xenstore: watch notifications lacking permission checks (XSA-115 v3)</issue> <issue tracker="bnc" id="1027519">Xen: Missing upstream bug fixes</issue> <issue tracker="bnc" id="1179506">VUL-0: EMBARGOED: CVE-2020-29566: xen: undue recursion in x86 HVM context switch code (XSA-348 v2)</issue> <issue tracker="cve" id="2020-29484"/> <issue tracker="cve" id="2020-29481"/> <issue tracker="cve" id="2020-29483"/> <issue tracker="cve" id="2020-29570"/> <issue tracker="cve" id="2020-29566"/> <issue tracker="cve" id="2020-29571"/> <issue tracker="cve" id="2020-29480"/> <packager>charlesa</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for xen</summary> <description>This update for xen fixes the following issues: - CVE-2020-29480: Fixed an issue which could have allowed leak of non-sensitive data to administrator guests (bsc#117949 XSA-115). - CVE-2020-29481: Fixed an issue which could have allowd to new domains to inherit existing node permissions (bsc#1179498 XSA-322). - CVE-2020-29483: Fixed an issue where guests could disturb domain cleanup (bsc#1179502 XSA-325). - CVE-2020-29484: Fixed an issue where guests could crash xenstored via watchs (bsc#1179501 XSA-324). - CVE-2020-29566: Fixed an undue recursion in x86 HVM context switch code (bsc#1179506 XSA-348). - CVE-2020-29570: Fixed an issue where FIFO event channels control block related ordering (bsc#1179514 XSA-358). - CVE-2020-29571: Fixed an issue where FIFO event channels control structure ordering (bsc#1179516 XSA-359). - Fixed an issue where dump-core shows missing nr_pages during core (bsc#1176782). - Multiple other bugs (bsc#1027519) </description> </patchinfo>




