Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Debian: DSA-2337-1 Critical: Xen Local Access and DOS Issue

debian
Calendar Grey November 6, 2011
Scroller Debian
- ------------------------------------------------------------------------- Debian Security Advisory
Several vulnerabilities were discovered in the Xen virtual machine hypervisor

Summary

CVE-2011-1166

A 64-bit guest can get one of its vCPU'ss into non-kernel
mode without first providing a valid non-kernel pagetable,
thereby locking up the host system.

CVE-2011-1583, CVE-2011-3262

Local users can cause a denial of service and possibly execute
arbitrary code via a crafted paravirtualised guest kernel image.

CVE-2011-1898

When using PCI passthrough on Intel VT-d chipsets that do not
have interrupt remapping, guest OS can users to gain host OS
privileges by writing to the interrupt injection registers.

The oldstable distribution (lenny) contains a different version of Xen
not affected by these problems.

For the stable distribution (squeeze), this problem has been fixed in
version 4.0.1-4.

For the testing (wheezy) and unstable distribution (sid), this problem
has been fixed in version 4.1.1-1.

We recommend that you upgrade your xen packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
f...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xen
CVE ID: CVE-2011-1166 CVE-2011-1583 CVE-2011-1898 CVE-2011-3262

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.