Bug 31395 - xen-4.1: Multiple issues (3.1)
xen-4.1: Multiple issues (3.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.0
Other Linux
: P2 normal (vote)
: UCS 3.1-1-errata
Assigned To: Moritz Muehlenhoff
Janek Walkenhorst
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-21 09:14 CEST by Moritz Muehlenhoff
Modified: 2013-09-05 14:23 CEST (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2013-05-21 09:14:23 CEST
Missing input sanitising in the xc_vcpu_setaffinity() Python bindings (CVE-2013-2072)
Comment 1 Moritz Muehlenhoff univentionstaff 2013-06-04 07:46:32 CEST
Denial of service due to incorrect exception handling (CVE-2013-2077, CVE-2013-2078)

FPU information leak in XSAVE (CVE-2013-2076)


(These issues don't affect 2.4)
Comment 2 Moritz Muehlenhoff univentionstaff 2013-06-28 15:07:51 CEST
Denial of service through incorrrect preemption handling (CVE-2013-1432)

libxl incorrectly enforces permissions on xenstore keys (CVE-2013-2211)  (2.4 is not affected, libxl not used in UCS)

Multiple issues in libelf PV kernel handling (CVE-2013-2194, CVE-2013-2195, CVE-2013-2196)
Comment 3 Moritz Muehlenhoff univentionstaff 2013-07-25 07:45:26 CEST
Denial of service in HVM guests using PCI passthrough (CVE-2013-2212)
Comment 4 Moritz Muehlenhoff univentionstaff 2013-09-04 14:05:58 CEST
The following patches were backported and applied:
 - CVE-2013-1432
 - CVE-2013-2072
 - CVE-2013-2076
 - CVE-2013-2077
 - CVE-2013-2078

YAML file: 2013-09-04-xen-4.1.yaml


The fixes in CVE-2013-2194, CVE-2013-2195, CVE-2013-2196 are too intrusive to backport. An attack is limited to malicious images anyway.

CVE-2013-2211 doesn't apply to UCS, libxl isn't used.

CVE-2013-2212 is an unfixable hardware limitation.


Tests were succesful on amd64:
- Installing and running a PV UCS 3.1 system (amd64)
- Installing and running a Windows 7 (64 bit)
Comment 5 Moritz Muehlenhoff univentionstaff 2013-09-04 14:14:35 CEST
The Xen package in 3.2 is not identical; as such the patches were merged into the 3.2 branch and xen-4.1 rebuild for UCS 3.2.
Comment 6 Janek Walkenhorst univentionstaff 2013-09-05 12:51:59 CEST
Tests
 i386
  Win7(i386): OK
  UCS31(i386): OK
 amd64
  Win7(i386): OK
  UCS31(i386): OK
Changelog: OK
Advisory: OK
Patches: OK
UCS3.2-Import: OK
Comment 7 Moritz Muehlenhoff univentionstaff 2013-09-05 14:23:20 CEST
http://errata.univention.de/ucs/3.1/180.html