On Thursday, November 14, 2019 at 2:57:19 PM UTC+1, Andrew David Wong wrote:
>
> -----BEGIN PGP SIGNED MESSAGE----- 
> Hash: SHA512 
>
> On 2019-11-14 6:28 AM, Andrew David Wong wrote: 
> > On 2019-11-13 12:40 PM, Lorenzo Lamas wrote: 
> >> There are 2 new vulnerabilities in Intel CPU's, also affecting 
> >> Xen. Xen has issued XSA-304(CVE-2018-12207) and XSA 
> >> 305(CVE-2019-11135). Is the Qubes team aware yet? I haven't seen 
> >> a new QSB. 
> > 
> > 
> > Yes, we're aware. We're currently in the process of preparing 
> > announcements about these XSAs. 
> > 
> > Typically, XSAs have a predisclosure period, during which the XSA 
> > is embargoed, and the Qubes Security Team has time to analyze it 
> > and prepare patches and an announcement. However, these XSAs had 
> > no embargo period, so the Qubes Security Team had no advance notice 
> > of them before they were publicly announced. 
> > 
>
> The announcements have been published: 
>
> https://www.qubes-os.org/news/2019/11/13/xsa-304-qubes-not-affected/ 
>
> https://www.qubes-os.org/news/2019/11/13/qsb-053/ 
>
> - -- 
> Andrew David Wong (Axon) 
> Community Manager, Qubes OS 
> https://www.qubes-os.org 
>
> -----BEGIN PGP SIGNATURE----- 
>
> iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl3NXTIACgkQ203TvDlQ 
> MDB1tRAAwCpQCkP52V7LlN7TJGA2jdJGffw+Wp12l66m3fmY/y3FnxZnVBR8Q+Jm 
> rZ2TDW/khZVUyi3Oq8OH9BwClIBgO9k3HLu/Cjt68QoKsth24SRmufdzDicsBzJG 
> BFwXpX/uxJ7U08Ja1vlRWj3wln0pCc5xFKMkpDLMQ/3xaL/bAdXgMcxx5eAIUrjI 
> rd2V5UkqQsIFnEIfWyyVI45gcr8jCIb2P5TZ9yKuyKmHJQHBqYUlLwuc0cK+Az+J 
> 4SXwTMpp1H1F+iKhyageOgbCZQiVdxbodlw3rAyvA/rZ1zxogN+q27yfIkQu9TBO 
> Mj461YeX/bAHM35WNPJhCSH9Ivm/ahBGBCJxpwuZF9BWWE1gLfjQuZsEUQbJizjc 
> hn3oxsw2yFSg0bEuRJxkgHr9f/e2LnPDOc5lRJ/HY6ST2739CZfVgrxTV+4wKusv 
> c4/TGuXigOIKisLE3QBUFewZESbo6SfdLPDNHcgUWpunk66g/xMMGvTFIRcXbzWt 
> hKcnKj3+9qWFhJbuRF5VWDDuVIF0/biXglQAsUVM3q6xK5OKDTjXGR6M/DvQGH68 
> sNEEOY8K+OcbGvX0188IGrrmK25i5X0z+0U4hFJFOi8e1iKh24a6cCi9hJ//Sotj 
> q0t5EUspfPzz7i6yE/FU1N0USZQSENtZKz18LV+NsEiQoO9qDaU= 
> =J53Z 
> -----END PGP SIGNATURE----- 
>
> Thank you, and thanks for the earlier explanation!
> Btw, do you think it is possible for Qubes to distribute the Intel 
> fTPM(http://tpm.fail/) update somehow like Qubes does with microcodes?
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4c7f4ddb-03e6-4894-a6d3-a3bb6fc64b41%40googlegroups.com.

Reply via email to