From 2648215258ade8d8d7ec33229395f596becae3c3 Mon Sep 17 00:00:00 2001 From: Fernando Rodrigues Date: Tue, 9 Sep 2025 22:45:20 +1000 Subject: [PATCH] xen: patch with XSA-472 Mutiple vulnerabilities in the Viridian interface There are multiple issues related to the handling and accessing of guest memory pages in the viridian code: 1. A NULL pointer dereference in the updating of the reference TSC area. This is CVE-2025-27466. 2. A NULL pointer dereference by assuming the SIM page is mapped when a synthetic timer message has to be delivered. This is CVE-2025-58142. 3. A race in the mapping of the reference TSC page, where a guest can get Xen to free a page while still present in the guest physical to machine (p2m) page tables. This is CVE-2025-58143. Signed-off-by: Fernando Rodrigues --- pkgs/by-name/xe/xen/package.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/pkgs/by-name/xe/xen/package.nix b/pkgs/by-name/xe/xen/package.nix index 9d6de3bcf682..ca36890f5904 100644 --- a/pkgs/by-name/xe/xen/package.nix +++ b/pkgs/by-name/xe/xen/package.nix @@ -3,6 +3,7 @@ stdenv, testers, fetchgit, + fetchpatch, replaceVars, # Xen @@ -184,6 +185,20 @@ stdenv.mkDerivation (finalAttrs: { ./0001-makefile-efi-output-directory.patch (replaceVars ./0002-scripts-external-executable-calls.patch scriptDeps) + + # XSA 472 + (fetchpatch { + url = "https://xenbits.xen.org/xsa/xsa472-1.patch"; + hash = "sha256-6k/X7KFno9uBG0mUtJxl7TMavaRs2Xlj9JlW9ai6p0k="; + }) + (fetchpatch { + url = "https://xenbits.xen.org/xsa/xsa472-2.patch"; + hash = "sha256-BisdztU9Wa5nIGmHo4IikqYPHdEhBehHaNqj1IuBe6I="; + }) + (fetchpatch { + url = "https://xenbits.xen.org/xsa/xsa472-3.patch"; + hash = "sha256-rikOofQeuLNMBkdQS3xzmwh7BlgMOTMSsQcAOEzNOso="; + }) ]; outputs = [