Univention Bugzilla – Bug 31395
xen-4.1: Multiple issues (3.1)
Last modified: 2013-09-05 14:23:20 CEST
Missing input sanitising in the xc_vcpu_setaffinity() Python bindings (CVE-2013-2072)
Denial of service due to incorrect exception handling (CVE-2013-2077, CVE-2013-2078) FPU information leak in XSAVE (CVE-2013-2076) (These issues don't affect 2.4)
Denial of service through incorrrect preemption handling (CVE-2013-1432) libxl incorrectly enforces permissions on xenstore keys (CVE-2013-2211) (2.4 is not affected, libxl not used in UCS) Multiple issues in libelf PV kernel handling (CVE-2013-2194, CVE-2013-2195, CVE-2013-2196)
Denial of service in HVM guests using PCI passthrough (CVE-2013-2212)
The following patches were backported and applied: - CVE-2013-1432 - CVE-2013-2072 - CVE-2013-2076 - CVE-2013-2077 - CVE-2013-2078 YAML file: 2013-09-04-xen-4.1.yaml The fixes in CVE-2013-2194, CVE-2013-2195, CVE-2013-2196 are too intrusive to backport. An attack is limited to malicious images anyway. CVE-2013-2211 doesn't apply to UCS, libxl isn't used. CVE-2013-2212 is an unfixable hardware limitation. Tests were succesful on amd64: - Installing and running a PV UCS 3.1 system (amd64) - Installing and running a Windows 7 (64 bit)
The Xen package in 3.2 is not identical; as such the patches were merged into the 3.2 branch and xen-4.1 rebuild for UCS 3.2.
Tests i386 Win7(i386): OK UCS31(i386): OK amd64 Win7(i386): OK UCS31(i386): OK Changelog: OK Advisory: OK Patches: OK UCS3.2-Import: OK
http://errata.univention.de/ucs/3.1/180.html