DSA-3554-1 xen -- xenID: oval:org.secpod.oval:def:602472 | Date: (C)2016-04-28 (M)2023-12-07 |
Class: PATCH | Family: unix |
Multiple vulnerabilities have been discovered in the Xen hypervisor. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2016-3158, CVE-2016-3159 Jan Beulich from SUSE discovered that Xen does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors. A malicious domain can take advantage of this flaw to obtain address space usage and timing information, about another domain, at a fairly low rate. CVE-2016-3960 Ling Liu and Yihan Lian of the Cloud Security Team, Qihoo 360 discovered an integer overflow in the x86 shadow pagetable code. A HVM guest using shadow pagetables can cause the host to crash. A PV guest using shadow pagetables with PV superpages enabled can crash the host, or corrupt hypervisor memory, potentially leading to privilege escalation.