stable

xen-4.4.3-3.fc21

FEDORA-2015-15946 created by myoung 10 years ago for Fedora 21

libxl fails to honour readonly flag on disks with qemu-xen [XSA-142 (possible fix)]


update to xen-4.4.3, including Use after free in QEMU/Xen block unplug protocol [XSA-139, CVE-2015-5166], QEMU leak of uninitialized heap memory in rtl8139 device model [XSA-140, CVE-2015-5165]

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2015-15946

This update has been submitted for testing by myoung.

10 years ago

This update has obsoleted xen-4.4.3-1.fc21, and has inherited its bugs and notes.

10 years ago

This update has been pushed to testing.

10 years ago

This update has been submitted for stable by myoung.

10 years ago

This update has been pushed to stable.

10 years ago

Please log in to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
10 years ago
in testing
10 years ago
in stable
10 years ago
BZ#1248760 CVE-2015-5165 Qemu: rtl8139 uninitialized heap memory information leakage to guest (XSA-140)
0
0
BZ#1248997 CVE-2015-5166 Qemu: BlockBackend object use after free issue (XSA-139)
0
0
BZ#1249756 CVE-2015-5165 xen: Qemu: rtl8139 uninitialized heap memory information leakage to guest [fedora-all]
0
0
BZ#1249757 CVE-2015-5166 xen: Qemu: BlockBackend object use after free issue [fedora-all]
0
0
BZ#1257893 Guests on Fedora22 Xen host are able to write to read-only disks with full device emulation type.
0
0

Automated Test Results