Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 536220 - <app-emulation/xen-{4.2.5-r4,4.3.3-r4,4.4.1-r5}: Use-after-free vulnerability (CVE-2015-0361)
Summary: <app-emulation/xen-{4.2.5-r4,4.3.3-r4,4.4.1-r5}: Use-after-free vulnerability...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-10 16:38 UTC by GLSAMaker/CVETool Bot
Modified: 2015-04-11 20:38 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2015-01-10 16:38:56 UTC
CVE-2015-0361 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0361):
  Use-after-free vulnerability in Xen 4.2.x, 4.3.x, and 4.4.x allows remote
  domains to cause a denial of service (system crash) via a crafted hypercall
  during HVM guest teardown.
Comment 1 Yixun Lan archtester gentoo-dev 2015-01-21 02:47:20 UTC
+  21 Jan 2015; Yixun Lan <dlan@gentoo.org> +xen-4.2.5-r4.ebuild,
+  +xen-4.3.3-r4.ebuild, +xen-4.4.1-r5.ebuild, -xen-4.5.0_rc4.ebuild,
+  +xen-4.5.0.ebuild:
+  version bump, fix security bug 536220
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2015-04-04 21:39:13 UTC
The current stabilized builds are:
4.4.2-r1
4.2.5-r8

With 4.3x removed.

Adding to existing GLSA release.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2015-04-11 20:38:07 UTC
This issue was resolved and addressed in
 GLSA 201504-04 at https://security.gentoo.org/glsa/201504-04
by GLSA coordinator Yury German (BlueKnight).