[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[xen staging-4.21] pygrub: security-supported only when run de-privileged



commit 6deb5262dffd096463cd8c7655c2ab88f83debf5
Author:     Jan Beulich <jbeulich@xxxxxxxx>
AuthorDate: Mon Jul 20 16:39:57 2026 +0100
Commit:     Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 28 13:07:36 2026 +0100

    pygrub: security-supported only when run de-privileged
    
    XSA-443 and XSA-497 addressed specific issues in specific file system
    drivers (libfsimage) used by pygrub. Further issues were reported, and yet
    more are to be expected. XSA-443 introduced a means to run pygrub de-
    privileged. Only this mode of operation is security supported from now on.
    
    This is XSA-508.
    
    Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
    Reviewed-by: Juergen Gross <jgross@xxxxxxxx>
    (cherry picked from commit 75f920bd47a4f59eaaa4596aa3f4e12a447d26d2)
---
 SUPPORT.md | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/SUPPORT.md b/SUPPORT.md
index fa20ad629c..71741be60e 100644
--- a/SUPPORT.md
+++ b/SUPPORT.md
@@ -288,6 +288,12 @@ or itself will not be regarded a security issue.
     Status, untrusted driver domains: Supported, not security supported
     Status, Liveupdate: Not functional
 
+## Guest boot loaders
+
+### Pygrub
+
+    Status: Supported, security supported only when run de-privileged
+
 ## Toolstack/3rd party
 
 ### libvirt driver for xl
--
generated by git-patchbot for /home/xen/git/xen.git#staging-4.21



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.