| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: xen-hypervisor | Distribution: Fedora Project |
| Version: 4.20.4 | Vendor: Fedora Project |
| Release: 1.fc43 | Build date: Thu Jul 30 23:04:32 2026 |
| Group: Unspecified | Build host: buildvm-x86-17.rdu3.fedoraproject.org |
| Size: 60632905 | Source RPM: xen-4.20.4-1.fc43.src.rpm |
| Packager: Fedora Project | |
| Url: http://xen.org/ | |
| Summary: Libraries for Xen tools | |
This package contains the Xen hypervisor
GPL-2.0-or-later AND LicenseRef-Callaway-LGPLv2+ AND LicenseRef-Callaway-BSD
* Thu Jul 30 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.4-1
- update to xen 4.20.4
- includes security fixes
x86 shadow paging is deprecated [XSA-495, CVE-2026-42493]
vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492]
buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494,
CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425]
sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426,
CVE-2026-62427]
grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428]
grant-table: version change racing with other operations [XSA-501,
CVE-2026-62435, CVE-2026-62436]
vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429]
x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430]
Viridian STIMER division by zero [XSA-504, CVE-2026-62431]
evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432]
correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433]
PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434]
pygrub is only supported in de-privileged mode [XSA-508]
* Thu Jun 18 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.3-4
[ never submitted as update ]
- x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487]
- domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490]
- Arm: Completion of memory accesses not guaranteed by completion of a TLBI
[XSA-493, CVE-2025-10263]
- x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]
* Tue May 12 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.3-3
- x86: CPU Opcode Cache corruption [XSA-490,CVE-2025-54518]
* Wed Apr 29 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.3-2
- oxenstored keeps quota related use counts across domain destruction
[XSA-483, CVE-2026-23556]
- Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557]
- grant table v2 race in status page mapping [XSA-486, CVE-2026-23558]
- x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]
* Fri Mar 27 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.3-1
- update to xen 4.20.3
remove patches now included or superceded upstream
* Wed Mar 18 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.2-4
- Use after free of paging structures in EPT [XSA-480, CVE-2026-23554]
- Xenstored DoS by unprivileged domain [XSA-481, CVE-2026-23555]
* Thu Jan 29 2026 Michael Young <m.a.young@durham.ac.uk> - 4.20.2-3
x86: buffer overrun with shadow paging + tracing [XSA-477, CVE-2025-58150]
(#2434046)
x86: incomplete IBPB for vCPU isolation [XSA-479, CVE-2026-23553]
(#2434048)
* Fri Nov 14 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.2-1.fc43
- update to xen 4.20.2
remove patches now included or superceded upstream
* Fri Oct 24 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.1-8
- Incorrect removal of permissions on PCI device unplug [XSA-476,
CVE-2025-58149]
* Tue Oct 21 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.1-7
- x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475,
CVE-2025-58147, CVE-2025-58148]
* Fri Sep 19 2025 Python Maint <python-maint@redhat.com> - 4.20.1-6
- Rebuilt for Python 3.14.0rc3 bytecode
* Wed Sep 10 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.1-5
- Mutiple vulnerabilities in the Viridian interface [XSA-472,
CVE-2025-27466, CVE-2025-58142, CVE-2025-58143]
- Arm issues with page refcounting [XSA-473, CVE-2025-58144,
CVE-2025-58145]
* Tue Sep 02 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.1-4
- tools/xl: don't crash on NULL command line
* Fri Aug 15 2025 Python Maint <python-maint@redhat.com> - 4.20.1-3
- Rebuilt for Python 3.14.0rc2 bytecode
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 4.20.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jul 13 2025 Michael Young <m.a.young@durham.ac.uk> - 4.20.1-1
- update to xen 4.20.1
remove old qemu code for spac file
remove armv7hl and ix86 code from spec file
update configuration in xen.hypervisor.config
minios is now a separate file
package extra ocaml files
unset -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 for hypervisor build
rebase xen.efi.build.patch
includes fixes for security vulnerabilites
x86: Incorrect stubs exception handling for flags recovery [XSA-470,
CVE-2025-27465]
x86: Transitive Scheduler Attacks [XSA-471, CVE-2024-36350,
CVE-2024-36357]
* Fri Jul 11 2025 Jerry James <loganjerry@gmail.com> - 4.19.2-6
- Rebuild to fix OCaml dependencies
* Mon Jun 02 2025 Python Maint <python-maint@redhat.com> - 4.19.2-5
- Rebuilt for Python 3.14
* Mon May 12 2025 Michael Young <m.a.young@durham.ac.uk> - 4.19.2-4
- x86: Indirect Target Selection [XSA-469, CVE-2024-28956]
* Mon Apr 07 2025 Michael Young <m.a.young@durham.ac.uk> - 4.19.2-2
- update to xen-4.19.2
remove patches now included or superceded upstream
remove xen*.efi.elf files to avoid debuginfo failure
* Thu Feb 27 2025 Michael Young <m.a.young@durham.ac.uk> - 4.19.1-7
- deadlock potential with VT-d and legacy PCI device pass-through
[XSA-467, CVE-2025-1713]
* Thu Jan 23 2025 Michael Young <m.a.young@durham.ac.uk> - 4.19.1-6
- adjust file locations now /usr/sbin is a symlink to /usr/bin
- remove debugedit fix as no longer needed
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 4.19.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jan 10 2025 Jerry James <loganjerry@gmail.com> - 4.19.1-4
- OCaml 5.3.0 rebuild for Fedora 42
* Thu Jan 09 2025 Michael Young <m.a.young@durham.ac.uk> - 4.19.1-3
- work around debugedit bug to fix aarch64 builds
* Sat Jan 04 2025 Andrea Perotti <aperotti@redhat.com> - 4.19.1-2
- xen-hypervisor %post doesn't load all needed grub2 modules
(#2335558)
* Thu Dec 05 2024 Michael Young <m.a.young@durham.ac.uk> - 4.19.1-1
- update to xen-4.19.1
remove patches now included or superceded upstream
* Tue Nov 12 2024 Michael Young <m.a.young@durham.ac.uk> - 4.19.0-5
- Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818]
- libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]
- additional patches so above applies cleanly
* Tue Sep 24 2024 Michael Young <m.a.young@durham.ac.uk> - 4.19.0-4
- x86: Deadlock in vlapic_error() [XSA-462, CVE-2024-45817] (#2314782)
* Wed Sep 04 2024 Miroslav Suchý <msuchy@redhat.com> - 4.19.0-3
- convert license to SPDX
* Wed Aug 14 2024 Michael Young <m.a.young@durham.ac.uk> - 4.19.0-2
- error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145]
(#2314784)
- PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]
(#2314783)
* Sat Aug 03 2024 Michael Young <m.a.young@durham.ac.uk> - 4.19.0-1
- update to xen-4.19.0
rebase xen.fedora.systemd.patch, xen.efi.build.patch
xen.ocaml5.fixes.patch and xen.gcc14.fixes.patch
remove patches now included or superceded upstream
now need to enable systemd explicitly
xentrace_format has gone, pygrub is now only in /usr/libexec/xen/bin/
package xenwatchdogd.8.gz
use relative links for /usr/bin/qemu-system-i386
/boot/flask /boot/flask/xenpolicy-4.20.4 /boot/xen-4.20.4.config /boot/xen-4.20.4.gz /usr/lib/debug/.build-id /usr/lib/debug/.build-id/b6 /usr/lib/debug/.build-id/b6/80adf5ff9829211b0661092aa06d4dcbdd3b61 /usr/lib/debug/.build-id/b6/80adf5ff9829211b0661092aa06d4dcbdd3b61.debug /usr/lib/debug/xen-4.20.4.efi.map /usr/lib/debug/xen-syms-4.20.4 /usr/lib/debug/xen-syms-4.20.4.map /usr/lib64/efi/xen-4.20.4.efi /usr/lib64/efi/xen-4.20.4.notstripped.efi
Generated by rpm2html 1.8.1
Fabrice Bellet, Sat Aug 1 00:00:10 2026