Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 501080 - <app-emulation/xen-tools-{4.2.3-r1,4.3.1-r5}: use-after-free in xc_cpupool_getinfo() under memory pressure (XSA-88) (CVE-2014-1950)
Summary: <app-emulation/xen-tools-{4.2.3-r1,4.3.1-r5}: use-after-free in xc_cpupool_ge...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://xenbits.xen.org/xsa/advisory-8...
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-02-12 15:09 UTC by Tobias Heinlein (RETIRED)
Modified: 2015-01-03 21:22 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tobias Heinlein (RETIRED) gentoo-dev 2014-02-12 15:09:16 UTC
See $URL.
Comment 1 Yixun Lan archtester gentoo-dev 2014-02-13 08:32:11 UTC
fixed in
*xen-tools-4.3.1-r5 (13 Feb 2014)
*xen-tools-4.2.2-r7 (13 Feb 2014)

see bug #500530
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2014-05-21 03:37:30 UTC
Fixed as part of Bug 500530.

Adding to existing GLSA.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2014-07-16 16:47:00 UTC
This issue was resolved and addressed in
 GLSA 201407-03 at http://security.gentoo.org/glsa/glsa-201407-03.xml
by GLSA coordinator Mikle Kolyada (Zlogene).
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2015-01-03 21:22:17 UTC
CVE-2014-1950 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-1950):
  Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x
  through 4.3.x, when using a multithreaded toolstack, does not properly
  handle a failure by the xc_cpumap_alloc function, which allows local users
  with access to management functions to cause a denial of service (heap
  corruption) and possibly gain privileges via unspecified vectors.