Fedora Linux 8695 Published by

A xen security update has been released for Fedora 37.



SECURITY: Fedora 37 Update: xen-4.16.2-2.fc37


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-d80cc73088
2022-11-10 22:04:44.630446
--------------------------------------------------------------------------------

Name : xen
Product : Fedora 37
Version : 4.16.2
Release : 2.fc37
URL :   http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

Arm: unbounded memory consumption for 2nd-level page tables [XSA-409,
CVE-2022-33747] P2M pool freeing may take excessively long [XSA-410,
CVE-2022-33746] lock order inversion in transitive grant copy handling [XSA-411,
CVE-2022-33748]
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 14 2022 Michael Young - 4.16.2-2
- Arm: unbounded memory consumption for 2nd-level page tables [XSA-409,
CVE-2022-33747]
- P2M pool freeing may take excessively long [XSA-410, CVE-2022-33746]
- lock order inversion in transitive grant copy handling [XSA-411,
CVE-2022-33748]
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2135262 - CVE-2022-33748 xen: lock order inversion in transitive grant copy handling
  https://bugzilla.redhat.com/show_bug.cgi?id=2135262
[ 2 ] Bug #2135267 - CVE-2022-33747 xen: unbounded memory consumption for 2nd-level page tables
  https://bugzilla.redhat.com/show_bug.cgi?id=2135267
[ 3 ] Bug #2135640 - CVE-2022-33746 xen: P2M pool freeing may take excessively long
  https://bugzilla.redhat.com/show_bug.cgi?id=2135640
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-d80cc73088' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________