Bug 470954
Summary: | [REG] kernel-xen 3.1.1 does not prevent modification of the CR4 TSC from applications (DoS possible) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Eugene Teo (Security Response) <eteo> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | anton, bburns, clalance, dhoward, dzickus, jpirko, kernel-maint, kreilly, lwang, xen-maint |
Target Milestone: | --- | Keywords: | Regression |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-02-18 09:07:03 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 377561, 470955, 470956 | ||
Bug Blocks: |
Description
Eugene Teo (Security Response)
2008-11-11 03:27:01 UTC
The fix for this has caused regressions in some systems. This bug is used to keep track of the regression to ensure that we resolve this ASAP. (In reply to comment #1) > The fix for this has caused regressions in some systems. This bug is used to > keep track of the regression to ensure that we resolve this ASAP. *this* refers to CVE-2007-5907. Thanks. (In reply to comment #3) > (In reply to comment #1) > > The fix for this has caused regressions in some systems. This bug is used to > > keep track of the regression to ensure that we resolve this ASAP. > > *this* refers to CVE-2007-5907. Thanks. Just to clarify. The fix for CVE-2007-5907 did not introduce a new security vulnerability. It introduced a normal bug where the kernel does not boot on certain hardware. I have removed the assigned CVE name, and Security keyword from the bugs. Thanks. The CVE and the regression caused by the initial patch has been solved in both the 5.2.z stream and 5.3. I'm not quite sure of the procedure with security bugs, but can we close this out now? Chris Lalancette Yes. Please close the bug, thanks. Great, thanks. Closing. |