[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[xen staging-4.17] pygrub: security-supported only when run de-privileged



commit d0f5c188481653c71c4909e80959d714be2a7f7d
Author:     Jan Beulich <jbeulich@xxxxxxxx>
AuthorDate: Mon Jul 20 16:46:06 2026 +0100
Commit:     Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 28 13:10:38 2026 +0100

    pygrub: security-supported only when run de-privileged
    
    XSA-443 and XSA-497 addressed specific issues in specific file system
    drivers (libfsimage) used by pygrub. Further issues were reported, and yet
    more are to be expected. XSA-443 introduced a means to run pygrub de-
    privileged. Only this mode of operation is security supported from now on.
    
    This is XSA-508.
    
    Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
    Reviewed-by: Juergen Gross <jgross@xxxxxxxx>
    (cherry picked from commit 75f920bd47a4f59eaaa4596aa3f4e12a447d26d2)
---
 SUPPORT.md | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/SUPPORT.md b/SUPPORT.md
index b040f95242..78ba8d46c5 100644
--- a/SUPPORT.md
+++ b/SUPPORT.md
@@ -208,6 +208,12 @@ Support for running qemu-xen device model in a linux 
stubdomain.
     Status, untrusted driver domains: Supported, not security supported
     Status, Liveupdate: Not functional
 
+## Guest boot loaders
+
+### Pygrub
+
+    Status: Supported, security supported only when run de-privileged
+
 ## Toolstack/3rd party
 
 ### libvirt driver for xl
--
generated by git-patchbot for /home/xen/git/xen.git#staging-4.17



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.