Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
(browse all)
updated 4 days, 8 hours ago by @SigmaSquadron Activity log
  • Created automatic suggestion
  • @SigmaSquadron dismissed
x86: buffer overrun with shadow paging + tracing

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the variable, and bounding of the writes was missing.

Affected products

Xen
  • ==consult Xen advisory XSA-477

Matching in nixpkgs

pkgs.xenomapper

Utility for post processing mapped reads that have been aligned to a primary genome and a secondary genome and binning reads into species specific, multimapping in each species, unmapped and unassigned bins

pkgs.nxengine-evo

Complete open-source clone/rewrite of the masterpiece jump-and-run platformer Doukutsu Monogatari (also known as Cave Story)

pkgs.grub2_pvgrub_image

PvGrub2 image for booting PV Xen guests

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.grub2_pvhgrub_image

PvGrub2 image for booting PVH Xen guests

  • nixos-unstable -
    • nixpkgs-unstable
    • nixos-unstable-small

pkgs.haskellPackages.xeno

A fast event-based XML parser in pure Haskell

pkgs.ocamlPackages.xenstore

Xenstore protocol in pure OCaml

pkgs.ocamlPackages.mirage-xen

Xen core platform libraries for MirageOS

pkgs.haskellPackages.xmlbf-xeno

xeno backend support for the xmlbf library

pkgs.ocamlPackages.xenstore-tool

Command line tool for interfacing with xenstore

pkgs.ocamlPackages.mirage-net-xen

Network device for reading and writing Ethernet frames via then Xen netfront/netback protocol

pkgs.python312Packages.pylatexenc

Simple LaTeX parser providing latex-to-unicode and unicode-to-latex conversion

pkgs.python313Packages.pylatexenc

Simple LaTeX parser providing latex-to-unicode and unicode-to-latex conversion

pkgs.ocamlPackages.mirage-bootvar-xen

Handle boot-time arguments for Xen platform

pkgs.ocamlPackages.xenstore_transport

Low-level libraries for connecting to a xenstore service on a xen host

Package maintainers

Already fixed.