Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2016-01-04 Thread David Vrabel
On 04/01/16 16:56, Marek Marczykowski-Górecki wrote: > On Mon, Jan 04, 2016 at 04:22:32PM +, David Vrabel wrote: >> On 04/01/16 13:06, Marek Marczykowski-Górecki wrote: >>> On Tue, Dec 22, 2015 at 10:06:25AM -0500, Eric Shelton wrote: The XSA mentions that "PV frontend patches will be deve

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2016-01-04 Thread Marek Marczykowski-Górecki
On Mon, Jan 04, 2016 at 04:22:32PM +, David Vrabel wrote: > On 04/01/16 13:06, Marek Marczykowski-Górecki wrote: > > On Tue, Dec 22, 2015 at 10:06:25AM -0500, Eric Shelton wrote: > >> The XSA mentions that "PV frontend patches will be developed and > >> released (publicly) after the embargo dat

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2016-01-04 Thread David Vrabel
On 04/01/16 13:06, Marek Marczykowski-Górecki wrote: > On Tue, Dec 22, 2015 at 10:06:25AM -0500, Eric Shelton wrote: >> The XSA mentions that "PV frontend patches will be developed and >> released (publicly) after the embargo date." Has anything been done >> towards this that should also be incorp

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2016-01-04 Thread Konrad Rzeszutek Wilk
On Mon, Jan 04, 2016 at 02:06:32PM +0100, Marek Marczykowski-Górecki wrote: > On Tue, Dec 22, 2015 at 10:06:25AM -0500, Eric Shelton wrote: > > The XSA mentions that "PV frontend patches will be developed and > > released (publicly) after the embargo date." Has anything been done > > towards this

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2016-01-04 Thread Marek Marczykowski-Górecki
On Tue, Dec 22, 2015 at 10:06:25AM -0500, Eric Shelton wrote: > The XSA mentions that "PV frontend patches will be developed and > released (publicly) after the embargo date." Has anything been done > towards this that should also be incorporated into MiniOS? On a > system utilizing a "driver dom

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2015-12-22 Thread Eric Shelton
The XSA mentions that "PV frontend patches will be developed and released (publicly) after the embargo date." Has anything been done towards this that should also be incorporated into MiniOS? On a system utilizing a "driver domain," where a backend is running on a domain that is considered unpriv

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2015-12-22 Thread Samuel Thibault
Stefano Stabellini, on Tue 22 Dec 2015 12:24:35 +, wrote: > MiniOS for QEMU stubdom has frontends, such as mini-os/blkfront.c and > mini-os/netfront.c, not backends. There is one backend, tpmback. It however doesn't use a ring. Samuel ___ Xen-deve

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2015-12-22 Thread Stefano Stabellini
MiniOS for QEMU stubdom has frontends, such as mini-os/blkfront.c and mini-os/netfront.c, not backends. Cheers, Stefano On Mon, 21 Dec 2015, Eric Shelton wrote: > Seeing as "All OSes providing PV backends are susceptible," doesn't this > include MiniOS for QEMU stubdom as well?  > Are there pa

Re: [Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory

2015-12-21 Thread Eric Shelton
Seeing as "All OSes providing PV backends are susceptible," doesn't this include MiniOS for QEMU stubdom as well? Are there patches available for mini-os/blkfront.c, mini-os/netfront.c, and mini-os/pcifront.c? I didn't see anything for this. Best, Eric On Thu, Dec 17, 2015 at 1:36 PM, Xen.org s

[Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory contents

2015-12-17 Thread Xen . org security team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Xen Security Advisory CVE-2015-8550 / XSA-155 version 6 paravirtualized drivers incautious about shared memory contents UPDATES IN VERSION 6 Correct CREDITS section. ISSUE DESCRIPTI

[Xen-devel] Xen Security Advisory 155 (CVE-2015-8550) - paravirtualized drivers incautious about shared memory contents

2015-12-17 Thread Xen . org security team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Xen Security Advisory CVE-2015-8550 / XSA-155 version 5 paravirtualized drivers incautious about shared memory contents UPDATES IN VERSION 5 Public release. ISSUE DESCRIPTION ==