Bug 35222 - xen new security issues CVE-2026-2355[45]
Summary: xen new security issues CVE-2026-2355[45]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-03-17 13:23 CET by Nicolas Salguero
Modified: 2026-03-25 18:32 CET (History)
4 users (show)

See Also:
Source RPM: xen-4.17.5-1.git20251028.2.mga9.src.rpm
CVE: CVE-2026-23554
Status comment:


Attachments

Description Nicolas Salguero 2026-03-17 13:23:16 CET
References:
CVE-2026-23554: https://www.openwall.com/lists/oss-security/2026/03/17/6
CVE-2026-23555: https://www.openwall.com/lists/oss-security/2026/03/17/7

Mageia 9 is only affected by CVE-2026-23554.
Nicolas Salguero 2026-03-17 13:25:05 CET

Flags: (none) => affects_mga9+
CVE: (none) => CVE-2026-23554, CVE-2026-23555
Status comment: (none) => Patches available from upstream
Source RPM: (none) => xen-4.20.2-2.mga10.src.rpm, xen-4.17.5-1.git20251028.2.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2026-03-17 13:38:57 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use after free of paging structures in EPT. (CVE-2026-23554)

References:
https://www.openwall.com/lists/oss-security/2026/03/17/6
========================

Updated packages in core/updates_testing:
========================
lib(64)xen-devel-4.17.5-1.git20251028.3.mga9
lib(64)xen3.0-4.17.5-1.git20251028.3.mga9
ocaml-xen-4.17.5-1.git20251028.3.mga9
ocaml-xen-devel-4.17.5-1.git20251028.3.mga9
xen-4.17.5-1.git20251028.3.mga9
xen-hypervisor-4.17.5-1.git20251028.3.mga9
xen-licenses-4.17.5-1.git20251028.3.mga9
xen-runtime-4.17.5-1.git20251028.3.mga9

from SRPM:
xen-4.17.5-1.git20251028.3.mga9.src.rpm

Status: NEW => ASSIGNED
Status comment: Patches available from upstream => (none)
Flags: affects_mga9+ => (none)
Source RPM: xen-4.20.2-2.mga10.src.rpm, xen-4.17.5-1.git20251028.2.mga9.src.rpm => xen-4.17.5-1.git20251028.2.mga9.src.rpm
Whiteboard: MGA9TOO => (none)
CVE: CVE-2026-23554, CVE-2026-23555 => CVE-2026-23554
Assignee: bugsquad => qa-bugs
Version: Cauldron => 9

katnatek 2026-03-18 01:33:06 CET

Keywords: (none) => advisory

Comment 2 Len Lawrence 2026-03-23 01:38:17 CET
Mageia9, x86_64

Installed the release packages and then updated using qarepo.
No problems there but not having any knowledge of hypervisors have to leave things there.

Not able to experiment because it has been impossible to install virtualboxes on my existing systems for the last two or three years and any previous vboxes have now disappeared due to the demise of their hosts.

So, good as far as updating goes but actual testing must depend on other users.

CC: (none) => tarazed25

Comment 3 katnatek 2026-03-23 01:42:19 CET
clean update should be enough, still can't test th Mageia with Xen Hypervisor
item in grub

Whiteboard: (none) => MGA9-64-OK

Comment 4 Len Lawrence 2026-03-23 01:45:38 CET
In reply to Len Lawrence in comment 2:
The hardware is all ASUS based so probably not vulnerable to the EPT bug.

In reply to katnatek in comment 3 - noted.
Comment 5 Thomas Andrews 2026-03-25 16:18:30 CET
MGA9-64 Plasma, i5-7500, Nvidia Quadro K620 graphics. 

Started Gnome Boxes, which had not been run in months on this system, ran an existing MGA9 Plasma VM, to make sure it was still working before the update.

The following 2 packages are going to be installed:

- lib64xen3.0-4.17.5-1.git20251028.3.mga9.x86_64
- xen-licenses-4.17.5-1.git20251028.3.mga9.x86_64

8B of additional disk space will be used.

673KB of packages will be retrieved.

No installation issues. Ran Boxes again, and started the VM. Expanded it to full screen, used Gwenview to look at some photos. Started MCC and went after updates - 160 in all, including glibc and a kernel. Rebooted to a still-functioning desktop.

No issues noted, looks OK to me.

Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 6 Dan Fandrich 2026-03-25 17:48:46 CET
The advisory contains a different version number than given in comment 1. I'm taking the liberty of changing it since that's the only version in updates_testing and matches the version shown to have been tested in comment 5.

CC: (none) => dan

Comment 7 Mageia Robot 2026-03-25 18:32:23 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0068.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.