ubuntu/+source/xen:applied/ubuntu/zesty-updates

Last commit made on 2017-10-16
Get this branch:
git clone -b applied/ubuntu/zesty-updates https://git.launchpad.net/ubuntu/+source/xen
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
applied/ubuntu/zesty-updates
Repository:
lp:ubuntu/+source/xen

Recent commits

c1937b2... by Stefan Bader on 2017-10-11

Import patches-applied version 4.8.0-1ubuntu2.4 to applied/ubuntu/zesty-security

Imported using git-ubuntu import.

Changelog parent: 193ef13050adeab7e564ebd4d2c1756968fb01d0
Unapplied parent: 53a3f4797010b030243929d12dae324b2224dc63

New changelog entries:
  * Applying Xen Security Advisories:
    - CVE-2017-14316 / XSA-231
      - xen/mm: make sure node is less than MAX_NUMNODES
    - CVE-2017-14318 / XSA-232
      - grant_table: fix GNTTABOP_cache_flush handling
    - CVE-2017-14317 / XSA-233
      - tools/xenstore: dont unlink connection object twice
    - CVE-2017-14319 / XSA-234
      - gnttab: also validate PTE permissions upon destroy/replace
    - XSA-235
      - arm/mm: release grant lock on xenmem_add_to_physmap_one() error paths
    - XSA-237
      - x86: don't allow MSI pIRQ mapping on unowned device
      - x86: enforce proper privilege when (un)mapping pIRQ-s
      - x86/MSI: disallow redundant enabling
      - x86/IRQ: conditionally preserve irq <-> pirq mapping on map error
        paths
      - x86/FLASK: fix unmap-domain-IRQ XSM hook
    - XSA-238
      - x86/ioreq server: correctly handle bogus
        XEN_DMOP_{,un}map_io_range_to_ioreq_server arguments
    - XSA-239
      - x86/HVM: prefill partially used variable on emulation paths
    - XSA-240
      - x86: limit linear page table use to a single level
      - x86/mm: Disable PV linear pagetables by default
    - XSA-241
      - x86: don't store possibly stale TLB flush time stamp
    - XSA-242
      - x86: don't allow page_unlock() to drop the last type reference
    - XSA-243
      - x86/shadow: Don't create self-linear shadow mappings for 4-level
        translated guests
    - XSA-244
      - x86/cpu: Fix IST handling during PCPU bringup
    - XSA-245
      - xen/page_alloc: Cover memory unreserved after boot in first_valid_mfn
      - xen/arm: Correctly report the memory region in the dummy NUMA helpers
  * Applying Xen Security Advisories:
    - XSA-226 / CVE-2017-12135
      - gnttab: don't use possibly unbounded tail calls
      - gnttab: fix transitive grant handling
    - XSA-227 / CVE-2017-12137
      - x86/grant: Disallow misaligned PTEs
    - XSA-228 / CVE-2017-12136
      - gnttab: split maptrack lock to make it fulfill its purpose again
    - XSA-230 / CVE-2017-12855
      - gnttab: correct pin status fixup for copy

53a3f47... by Stefan Bader on 2017-10-11

[PATCH 2/2] xen/arm: Correctly report the memory region in the dummy

Gbp-Pq: xsa245-0002-xen-arm-Correctly-report-the-memory-region-in-the-du.patch.

18455a9... by Stefan Bader on 2017-10-11

[PATCH 1/2] xen/page_alloc: Cover memory unreserved after boot in

Gbp-Pq: xsa245-0001-xen-page_alloc-Cover-memory-unreserved-after-boot-in.patch.

2ec8859... by Stefan Bader on 2017-10-11

[PATCH] x86/cpu: Fix IST handling during PCPU bringup

Gbp-Pq: xsa244.patch.

fabe420... by Stefan Bader on 2017-10-11

x86/shadow: Don't create self-linear shadow mappings for 4-level translated guests

Gbp-Pq: xsa243-4.8.patch.

c6b5777... by Stefan Bader on 2017-10-11

x86: don't allow page_unlock() to drop the last type reference

Gbp-Pq: xsa242-4.9.patch.

b6a8e65... by Stefan Bader on 2017-10-11

x86: don't store possibly stale TLB flush time stamp

Gbp-Pq: xsa241-4.9.patch.

9747c2c... by Stefan Bader on 2017-10-11

[PATCH 2/2] x86/mm: Disable PV linear pagetables by default

Gbp-Pq: xsa240-4.8-0002-x86-mm-Disable-PV-linear-pagetables-by-default.patch.

ec70f6d... by Stefan Bader on 2017-10-11

[PATCH 1/2] x86: limit linear page table use to a single level

Gbp-Pq: xsa240-4.8-0001-x86-limit-linear-page-table-use-to-a-single-level.patch.

3f5f03b... by Stefan Bader on 2017-10-11

x86/HVM: prefill partially used variable on emulation paths

Gbp-Pq: xsa239.patch.