Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 543654 - app-emulation/xen: Multiple vulnerabilities (XSA-{125,126,127})
Summary: app-emulation/xen: Multiple vulnerabilities (XSA-{125,126,127})
Status: RESOLVED DUPLICATE of bug 545144
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-17 22:02 UTC by Kristian Fiskerstrand (RETIRED)
Modified: 2015-04-03 04:39 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-03-17 22:02:12 UTC
This is a tracking bug for the following Xen Security Advisories

              *** EMBARGOED UNTIL 2015-03-31 12:00 UTC ***

Xen Security Advisory XSA-125
Long latency MMIO mapping operations are not preemptible

Xen Security Advisory XSA-126
Unmediated PCI command register access in qemu

Xen Security Advisory XSA-127
Certain domctl operations may be abused to lock up the host

Details and patches are distributed by email to maintainers. Please prepare updated ebuilds for this while in embargo, but do not publish these in any public repository.
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2015-04-01 11:48:44 UTC
Issues are public
Comment 2 Ian Delaney (RETIRED) gentoo-dev 2015-04-02 02:12:45 UTC
at this point the xsa126 patches all fail to take
Comment 3 Ian Delaney (RETIRED) gentoo-dev 2015-04-03 01:07:49 UTC
at this next point the xsa126 patches tweaked by dlan work for both -qemuu and -qemut for 4.2, 4.4, 4.5 take fine. We have a leftover xsa126-qemuu-4.3.patch that appears to need a similar tweak.   Is there any gain in adding the 125 & 127 patches before that gets done?
Comment 4 Yixun Lan archtester gentoo-dev 2015-04-03 04:39:32 UTC

*** This bug has been marked as a duplicate of bug 545144 ***