Anzeigen der neuesten Beiträge
0 Mitglieder und 2 Gäste betrachten dieses Thema.
Xen 4.1.3 is a maintenance release in the 4.1 series and contains: Fixes for the following critical vulnerabilities: We recommend all users of the 4.0 and 4.1 stable series to update to these latest point releases. CVE-2012-0217 / XSA-7: PV guest privilege escalation vulnerability CVE-2012-0218 / XSA-8: guest denial of service on syscall/sysenter exception generation CVE-2012-2934 / XSA-9: PV guest host Denial of Service CVE-2012-3432 / XSA-10: HVM guest user mode MMIO emulation DoS vulnerability CVE-2012-3433 / XSA-11: HVM guest destroy p2m teardown host DoS vulnerabilit Among many bug fixes and improvements (over 100 since Xen 4.1.2). Highlights are: Updates for the latest Intel/AMD CPU revisions Bug fixes and improvements to the libxl tool stack Bug fixes for IOMMU handling (device passthrough to HVM guests) Bug fixes for host kexec/kdumpIt also contains the following fixes from earlier maintenance releases: Security fixes including CVE-2011-1583 and CVE-2011-1898 Enhancements to guest introspection (VM single stepping support for very fine-grained access control) Many stability improvements, such as: PV-on-HVM stability fixes (fixing some IRQ issues) XSAVE cpu feature support for PV guests (allows safe use of latest multimedia instructions) RAS fixes for high availability fixes for offlining bad pages changes to libxc, mainly of benefit to libvirt New XL toolstack Debug support: kexec/kdump Remus (High Availability) Device passthrough to HVM guests Interrupt handling Support for Supervisor Mode Execution Protection (SMEP) Compatibility fixes for newer Linux guests, newer compilers, some old guest savefiles, newer Python, grub2, some hardware/BIOS bugs.
This fixes the following critical vulnerabilities: CVE-2013-1922 / XSA-48 qemu-nbd format-guessing due to missing format specification CVE-2013-2007 / XSA-51 qemu guest agent (qga) insecure file permissions CVE-2013-1442 / XSA-62 Information leak on AVX and/or LWP capable CPUs CVE-2013-4355 / XSA-63 Information leaks through I/O instruction emulation CVE-2013-4356 / XSA-64 Memory accessible by 64-bit PV guests under live migration CVE-2013-4361 / XSA-66 Information leak through fbld instruction emulation CVE-2013-4368 / XSA-67 Information leak through outs instruction emulation CVE-2013-4369 / XSA-68 possible null dereference when parsing vif ratelimiting info CVE-2013-4370 / XSA-69 misplaced free in ocaml xc_vcpu_getaffinity stub CVE-2013-4371 / XSA-70 use-after-free in libxl_list_cpupool under memory pressure CVE-2013-4375 / XSA-71 qemu disk backend (qdisk) resource leak CVE-2013-4416 / XSA-72 ocaml xenstored mishandles oversized message replies