Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-15-SP1:Update
xen
xsa376.patch
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File xsa376.patch of Package xen
Subject: SUPPORT.md: limit support statement for Linux and Windows frontends From: Juergen Gross jgross@suse.com Tue Jan 11 11:43:48 2022 +0100 Date: Tue Jan 11 11:43:48 2022 +0100: Git: 22891e12a45f9bb2e1dbb5daf2ba39cbe002e4f4 Change the support state of Linux and Windows pv frontends from "supported" to "supported with caveats" in order to reflect that the frontends can probably be harmed by their respective backends. Some of the Linux frontends have been hardened already. This is XSA-376 Signed-off-by: Juergen Gross <jgross@suse.com> Acked-by: Jan Beulich <jbeulich@suse.com> --- a/SUPPORT.md +++ b/SUPPORT.md @@ -364,7 +364,11 @@ Guest-side driver capable of speaking th Status, FreeBSD: Supported, Security support external Status, NetBSD: Supported, Security support external Status, OpenBSD: Supported, Security support external - Status, Windows: Supported + Status, Windows: Supported, with caveats + +Windows frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### Netfront @@ -374,13 +378,22 @@ Guest-side driver capable of speaking th Status, FreeBSD: Supported, Security support external Status, NetBSD: Supported, Security support external Status, OpenBSD: Supported, Security support external - Status, Windows: Supported + Status, Windows: Supported, with caveats + +Windows frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### PV Framebuffer (frontend) Guest-side driver capable of speaking the Xen PV Framebuffer protocol Status, Linux (xen-fbfront): Supported + Status, Linux (xen-fbfront): Supported, with caveats + +Linux frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### PV Console (frontend) @@ -389,18 +402,30 @@ Guest-side driver capable of speaking th Status, Linux (hvc_xen): Supported Status, FreeBSD: Supported, Security support external Status, NetBSD: Supported, Security support external - Status, Windows: Supported + Status, Windows: Supported, with caveats + +Windows frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### PV keyboard (frontend) Guest-side driver capable of speaking the Xen PV keyboard protocol. Note that the "keyboard protocol" includes mouse / pointer support as well. - Status, Linux (xen-kbdfront): Supported + Status, Linux (xen-kbdfront): Supported, with caveats + +Linux frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### PV USB (frontend) - Status, Linux: Supported + Status, Linux: Supported, with caveats + +Linux frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. ### PV SCSI protocol (frontend) @@ -409,6 +434,10 @@ Note that the "keyboard protocol" includ NB that while the PV SCSI frontend is in Linux and tested regularly, there is currently no xl support. +Linux frontend currently trusts the backend; +bugs in the frontend which allow backend to cause mischief will not be +considered security vulnerabilities. + ### PV TPM (frontend) Guest-side driver capable of speaking the Xen PV TPM protocol @@ -895,6 +924,9 @@ are given the following labels: This feature is security supported by a different organization (not the XenProject). + The extent of support is defined by that organization. + It might be limited, e.g. like described in **Supported, with caveats** + below. See **External security support** below. * **Supported, with caveats**
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor