Bug 1176097 (CVE-2015-0361, xsa116)
Summary: | CVE-2015-0361 kernel: xen crash due to use after free on hvm guest teardown (xsa116) | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> | ||||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||
Status: | CLOSED NOTABUG | QA Contact: | |||||||
Severity: | medium | Docs Contact: | |||||||
Priority: | medium | ||||||||
Version: | unspecified | CC: | drjones, imammedo, jrusnack, mrezanin, pbonzini, pmatouse, rkrcmar, security-response-team, vkuznets | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2015-03-31 15:53:31 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Bug Depends On: | 1179221 | ||||||||
Bug Blocks: | 1175385 | ||||||||
Attachments: |
|
Description
Vasyl Kaigorodov
2014-12-19 12:03:06 UTC
Created attachment 971110 [details]
xsa116.patch
Created attachment 971111 [details]
xsa116-4.3-4.2.patch
Acknowledgements: Red Hat would like to thank the Xen project for reporting this issue. External References: http://xenbits.xen.org/xsa/advisory-116.html Created xen tracking bugs for this issue: Affects: fedora-all [bug 1179221] xen-4.4.1-12.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. xen-4.3.3-9.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. Statement: Not vulnerable. This issue does not affect the kernel-xen packages as shipped with Red Hat Enterprise Linux 5. |