Xen (XSA-500, XSA-505, XSA-506, XSA-507) security updates for Qubes OS released

Published by

Qubes Security Bulletin 116 has announced the release of security updates for four new Xen vulnerabilities (XSA-500, XSA-505, XSA-506, and XSA-507) that pose risks of system memory compromise or sensitive data leakage in Qubes OS. While the default configuration is at moderate risk, administrators with certain workloads should prioritize addressing these vulnerabilities. Users operating on Qubes OS 4.3 can resolve the issues by upgrading to Xen package version 4.19.5-2 and rebooting their systems, and those using Anti Evil Maid protection will need to reseal their secret passphrase due to changes in PCR values. The vulnerabilities affect various systems based on their configuration, with specific risks associated with paravirtualized workloads and untrusted HVM qubes



Xen (XSA-500, XSA-505, XSA-506, XSA-507) security updates for Qubes OS released

Qubes Security Bulletin 116 addresses four new Xen vulnerabilities (XSA-500, XSA-505, XSA-506, and XSA-507) that could allow malicious virtual machines to compromise system memory or leak sensitive data across isolated qubes. While the default Qubes OS configuration faces moderate risk, administrators running paravirtualized workloads, untrusted HVM qubes, or templates with active memory balancing should treat these flaws as high priority. Systems operating on Qubes OS 4.3 can resolve the issues by upgrading dom0 to Xen package version 4.19.5-2 through the standard update tool and then rebooting the machine. Anyone who previously enabled Anti Evil Maid protection must also reseal their secret passphrase, since the updated binaries shift PCR values 18 and 19.

QSB-116: Multiple Xen issues (XSA-500, XSA-505, XSA-506, XSA-507)

Xen (XSA-500, XSA-505, XSA-506, XSA-507) security updates for Qubes OS released @ Linux Compatible