A flaw was found in the way xen_iret() used userspace alterable %ds. An unprivileged local guest user in the 32-bit PV Xen domain could use this flaw to crash the guest or, potentially, escalate their privileges.
Acknowledgements:
This issue was discovered by Andrew Jones of Red Hat.
Statement:
This issue did affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 6.
This issue did not affect Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.