On Thursday, November 14, 2019 at 2:57:19 PM UTC+1, Andrew David Wong wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > On 2019-11-14 6:28 AM, Andrew David Wong wrote: > > On 2019-11-13 12:40 PM, Lorenzo Lamas wrote: > >> There are 2 new vulnerabilities in Intel CPU's, also affecting > >> Xen. Xen has issued XSA-304(CVE-2018-12207) and XSA > >> 305(CVE-2019-11135). Is the Qubes team aware yet? I haven't seen > >> a new QSB. > > > > > > Yes, we're aware. We're currently in the process of preparing > > announcements about these XSAs. > > > > Typically, XSAs have a predisclosure period, during which the XSA > > is embargoed, and the Qubes Security Team has time to analyze it > > and prepare patches and an announcement. However, these XSAs had > > no embargo period, so the Qubes Security Team had no advance notice > > of them before they were publicly announced. > > > > The announcements have been published: > > https://www.qubes-os.org/news/2019/11/13/xsa-304-qubes-not-affected/ > > https://www.qubes-os.org/news/2019/11/13/qsb-053/ > > - -- > Andrew David Wong (Axon) > Community Manager, Qubes OS > https://www.qubes-os.org > > -----BEGIN PGP SIGNATURE----- > > iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl3NXTIACgkQ203TvDlQ > MDB1tRAAwCpQCkP52V7LlN7TJGA2jdJGffw+Wp12l66m3fmY/y3FnxZnVBR8Q+Jm > rZ2TDW/khZVUyi3Oq8OH9BwClIBgO9k3HLu/Cjt68QoKsth24SRmufdzDicsBzJG > BFwXpX/uxJ7U08Ja1vlRWj3wln0pCc5xFKMkpDLMQ/3xaL/bAdXgMcxx5eAIUrjI > rd2V5UkqQsIFnEIfWyyVI45gcr8jCIb2P5TZ9yKuyKmHJQHBqYUlLwuc0cK+Az+J > 4SXwTMpp1H1F+iKhyageOgbCZQiVdxbodlw3rAyvA/rZ1zxogN+q27yfIkQu9TBO > Mj461YeX/bAHM35WNPJhCSH9Ivm/ahBGBCJxpwuZF9BWWE1gLfjQuZsEUQbJizjc > hn3oxsw2yFSg0bEuRJxkgHr9f/e2LnPDOc5lRJ/HY6ST2739CZfVgrxTV+4wKusv > c4/TGuXigOIKisLE3QBUFewZESbo6SfdLPDNHcgUWpunk66g/xMMGvTFIRcXbzWt > hKcnKj3+9qWFhJbuRF5VWDDuVIF0/biXglQAsUVM3q6xK5OKDTjXGR6M/DvQGH68 > sNEEOY8K+OcbGvX0188IGrrmK25i5X0z+0U4hFJFOi8e1iKh24a6cCi9hJ//Sotj > q0t5EUspfPzz7i6yE/FU1N0USZQSENtZKz18LV+NsEiQoO9qDaU= > =J53Z > -----END PGP SIGNATURE----- > > Thank you, and thanks for the earlier explanation! > Btw, do you think it is possible for Qubes to distribute the Intel > fTPM(http://tpm.fail/) update somehow like Qubes does with microcodes? >
-- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/4c7f4ddb-03e6-4894-a6d3-a3bb6fc64b41%40googlegroups.com.
