Xen: Multiple Vulnerabilities — GLSA 202402-07

Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.

Affected packages

app-emulation/xen on all architectures
Affected versions < 4.16.6_pre1
Unaffected versions >= 4.16.6_pre1

Background

Xen is a bare-metal hypervisor.

Description

Multiple vulnerabilities have been discovered in Xen. Please review the CVE identifiers referenced below for details.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

All Xen users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.16.6_pre1"
 

References

Release date
February 04, 2024

Latest revision
February 04, 2024: 1

Severity
high

Exploitable
remote

Bugzilla entries