Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 24: 2016-9-13 Moderate: Xen Flaws and Misconfigurations

fedora
Calendar Grey September 13, 2016
Dist Fedora Esm H88
Xen updates for Fedora 24 implement restrictions on L3 nesting, correct truncation of instruction pointers, and resolve overflow vulnerabilities.
x86: Disallow L3 recursive pagetable for 32-bit PV guests [XSA-185, CVE-2016-7092] (#1374470) x86: Mishandling of instruction pointer truncation during emulation [XSA-186, CVE-2016...

Summary

This package contains the XenD daemon and xm command line

tools, needed to manage virtual machines running under the

Xen hypervisor

Update Information:

x86: Disallow L3 recursive pagetable for 32-bit PV guests [XSA-185, CVE-2016-7092] (#1374470) x86: Mishandling of instruction pointer truncation during emulation [XSA-186, CVE-2016-7093] (#1374471) x86 HVM: Overflow of sh_ctxt->seg_reg[] [XSA-187, CVE-2016-7094] (#1374473)

Change Log

References


[ 1 ] Bug #1370319 - CVE-2016-7092 xen: x86: Disallow L3 recursive pagetable for 32-bit PV guests https://bugzilla.redhat.com/show_bug.cgi?id=1370319 [ 2 ] Bug #1370322 - CVE-2016-7093 xen: x86: Mishandling of instruction pointer truncation during emulation https://bugzilla.redhat.com/show_bug.cgi?id=1370322 [ 3 ] Bug #1370332 - CVE-2016-7094 xen: x86 HVM: Overflow of sh_ctxt->seg_reg[] https://bugzilla.redhat.com/show_bug.cgi?id=1370332

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update xen' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: xen
Product: Fedora 24
Version: 4.6.3
Release: 5.fc24
Summary: Xen is a virtual machine monitor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here