Bug 1148422

Summary: CVE-2014-7188 - Improper MSR range used for x2APIC emulation
Product: [Fedora] Fedora Reporter: Major Hayden 🤠 <mhayden>
Component: xenAssignee: Michael Young <m.a.young>
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 20CC: jforbes, kraxel, m.a.young, virt-maint
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-10-01 17:32:13 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
XSA-108 patch from Xen community none

Description Major Hayden 🤠 2014-10-01 12:34:30 UTC
Created attachment 943043 [details]
XSA-108 patch from Xen community

The Xen community has released details on XSA-108 / CVE-2014-7188 here:

  http://xenbits.xen.org/xsa/advisory-108.html
  https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188

It affects Xen 4.1+, so that's Fedora 19 through rawhide if I remember correctly.  The patch is available here:

  http://xenbits.xen.org/xsa/xsa108.patch

The bug allows an HVM guest (including PVHVM) to read ~ 3KB worth of memory from the hypervisor or other guests.

Comment 1 Michael Young 2014-10-01 17:32:13 UTC
#1148465 is tracking bug for this.

*** This bug has been marked as a duplicate of bug 1148465 ***