-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bf1da84dfc 2026-08-02 00:53:39.370682+00:00 --------------------------------------------------------------------------------
Name : xen Product : Fedora 44 Version : 4.21.2 Release : 1.fc44 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor
-------------------------------------------------------------------------------- Update Information:
update to xen 4.21.2 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508] -------------------------------------------------------------------------------- ChangeLog:
* Thu Jul 30 2026 Michael Young m.a.young@durham.ac.uk - 4.21.2-1 - update to xen 4.21.2 - includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508] --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bf1da84dfc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------