Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian: DSA-2544-1 Important: Xen Denial Of Service Vulnerability

debian
Calendar Grey September 8, 2012
Debian Logo
Enhance the Xen hypervisor to address various denial of service vulnerabilities in Debian, thereby boosting both system reliability and security.
Multiple denial of service vulnerabilities have been discovered in xen, an hypervisor

Summary

Multiple denial of service vulnerabilities have been discovered in xen,
an hypervisor. The Common Vulnerabilities and Exposures project identifies
the following problems:

CVE-2012-3494:

It was discovered that set_debugreg allows writes to reserved bits
of the DR7 debug control register on amd64 (x86-64) paravirtualised
guests, allowing a guest to crash the host.

CVE-2012-3496:

Matthew Daley discovered that XENMEM_populate_physmap, when called
with the MEMF_populate_on_demand flag set, a BUG (detection routine)
can be triggered if a translating paging mode is not being used,
allowing a guest to crash the host.

For the stable distribution (squeeze), these problems have been fixed in
version 4.0.1-5.4.

For the testing distribution (wheezy), these problems will be fixed
soon.

For the unstable distribution (sid), these problems have been fixed in
version 4.1.3-2.

We recommend that you upgrade your xen packages.

Further information about Debian Security Advisories, how to apply
th...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: xen
CVE ID: CVE-2012-3494 CVE-2012-3496

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here