Xen "arch_set_info_guest()" Denial of Service (2)

by Carol~ Moderator - 3/17/11 7:57 AM

In Reply to: VULNERABILITIES / FIXES - March 17, 2011 by Carol~ Moderator

Release Date : 2011-03-17

Criticality level : Not critical
Impact : DoS
Where : Local system
Solution Status: Vendor Workaround

Software: Xen 3.x

Description:
A vulnerability has been reported in Xen, which can be exploited by malicious, local users in a guest virtual machine to cause a DoS (Denial of Service).

The vulnerability is caused due to an error within the "arch_set_info_guest()" function in xen/arch/x86/domain.c.

Solution:
Fixed in the Mercurial repository.

Provided and/or discovered by:
Reported in a SUSE bug by Jan Beulich.

Original Advisory:
SUSE Bug #679344:
https://bugzilla.novell.com/show_bug.cgi?id=679344

Xen commit:
http://xenbits.xen.org/hg/staging/xen-unstable.hg/rev/c79aae866ad8

http://secunia.com/advisories/43803/