Bug 33401 - xen new security issues CVE-2024-3114[34], CVE-2024-3114[56]
Summary: xen new security issues CVE-2024-3114[34], CVE-2024-3114[56]
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Giuseppe Ghibò
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-16 14:10 CEST by Nicolas Salguero
Modified: 2024-09-02 12:03 CEST (History)
0 users

See Also:
Source RPM: xen-4.18.0-5.mga10.src.rpm, xen-4.17.4-1.mga9.src.rpm
CVE: CVE-2024-31143, CVE-2024-31144, CVE-2024-31145, CVE-2024-31146
Status comment:


Attachments

Nicolas Salguero 2024-07-16 14:11:32 CEST

CVE: (none) => CVE-2024-31143, CVE-2024-31144
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => xen-4.18.0-5.mga10.src.rpm, xen-4.17.4-1.mga9.src.rpm

Comment 1 Lewis Smith 2024-07-17 21:45:32 CEST
"xsa458.patch"
https://www.openwall.com/lists/oss-security/2024/07/16/3/1

"xsa459-xen-api.patch"
https://www.openwall.com/lists/oss-security/2024/07/16/4/1
"xsa459-xsconsole.patch"
https://www.openwall.com/lists/oss-security/2024/07/16/4/2

It looks as if you do xen, Nicolas; so handing this to you.

Assignee: bugsquad => nicolas.salguero

Nicolas Salguero 2024-07-18 09:06:13 CEST

Assignee: nicolas.salguero => ghibomgx

Comment 2 Nicolas Salguero 2024-09-02 12:03:11 CEST
CVE-2024-3114[56] were announced here:
https://openwall.com/lists/oss-security/2024/08/14/2
https://openwall.com/lists/oss-security/2024/08/14/3

CVE: CVE-2024-31143, CVE-2024-31144 => CVE-2024-31143, CVE-2024-31144, CVE-2024-31145, CVE-2024-31146
Summary: xen new security issues CVE-2024-3114[34] => xen new security issues CVE-2024-3114[34], CVE-2024-3114[56]


Note You need to log in before you can comment on or make changes to this bug.