Описание
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| linux | fixed | 4.4~rc6-1~exp1 | experimental | package |
| linux | fixed | 4.3.3-3 | package | |
| linux-2.6 | removed | package | ||
| linux-2.6 | no-dsa | squeeze | package | |
| qemu | fixed | 1:2.5+dfsg-2 | package | |
| qemu | not-affected | wheezy | package | |
| qemu | not-affected | squeeze | package | |
| qemu-kvm | removed | package | ||
| qemu-kvm | not-affected | wheezy | package | |
| qemu-kvm | not-affected | squeeze | package | |
| xen | fixed | 4.8.0~rc3-1 | package | |
| xen | end-of-life | squeeze | package |
Примечания
http://xenbits.xen.org/xsa/advisory-155.html
https://git.kernel.org/linus/454d5d882c7e412b840e3c99010fe81a9862f6fb
https://git.kernel.org/linus/0f589967a73f1f30ab4ac4dd9ce0bb399b4d6357
https://git.kernel.org/linus/68a33bfd8403e4e22847165d149823a2e0e67c9c
https://git.kernel.org/linus/1f13d75ccb806260079e0679d55d9253e370ec8a
https://git.kernel.org/linus/18779149101c0dd43ded43669ae2a92d21b6f9cb
https://git.kernel.org/linus/be69746ec12f35b484707da505c6c76ff06f97dc
https://git.kernel.org/linus/8135cf8b092723dbfcc611fe6fdcb3a36c9951c5
Связанные уязвимости
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.