Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: <updates <at> fedoraproject.org>
Subject: [SECURITY] Fedora 15 Update: xen-4.1.1-3.fc15
Newsgroups: gmane.linux.redhat.fedora.package.announce
Date: Wednesday 31st August 2011 01:26:27 UTC (over 5 years ago)
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-10942
2011-08-17 00:09:14
--------------------------------------------------------------------------------

Name        : xen
Product     : Fedora 15
Version     : 4.1.1
Release     : 3.fc15
URL         : http://xen.org/
Summary     : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

untrusted guest controlling PCI[E] device can lock up
host CPU [CVE-2011-3131]
--------------------------------------------------------------------------------
ChangeLog:

* Sun Aug 14 2011 Michael Young  - 4.1.1-3
- untrusted guest controlling PCI[E] device can lock up host CPU
[CVE-2011-3131]
* Wed Jul 20 2011 Michael Young  - 4.1.1-2
- clean up patch to solve a problem with hvmloader compiled with gcc 4.6
* Wed Jun 15 2011 Michael Young  - 4.1.1-1
- update to 4.1.1
  includes various bugfixes and fix for [CVE-2011-1898] guest with pci
  passthrough can gain privileged access to base domain
- remove upstream cve-2011-1583-4.1.patch
* Mon May  9 2011 Michael Young  - 4.1.0-2
- Overflows in kernel decompression can allow root on xen PV guest to gain
  privileged access to base domain, or access to xen configuration info.
  Lack of error checking could allow DoS attack from guest [CVE-2011-1583]
- Don't require /usr/bin/qemu-nbd as it isn't used at present.
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xen' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on
the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
 
CD: 5ms