stable

xen-4.5.3-8.fc23

FEDORA-2016-103752d2a9 created by myoung 8 years ago for Fedora 23

Qemu: scsi: esp: OOB r/w access while processing ESP_FIFO [CVE-2016-5338] (#1343323) Qemu: scsi: megasas: information leakage in megasas_ctrl_get_info [CVE-2016-5337] (#1343909)


fix for CVE-2016-2858 doesn't build with qemu-xen enabled Unsanitised guest input in libxl device handling code [XSA-175, CVE-2016-4962] (#1342132) Unsanitised driver domain input in libxl device handling [XSA-178, CVE-2016-4963] (#1342131) arm: Host crash caused by VMID exhaust [XSA-181] (#1342530) Qemu: display: vmsvga: out-of-bounds read in vmsvga_fifo_read_raw() routine [CVE-2016-4454] (#1340741) Qemu: display: vmsvga: infinite loop in vmsvga_fifo_run() routine [CVE-2016-4453] (#1340746) Qemu: scsi: esp: OOB write when using non-DMA mode in get_cmd [CVE-2016-5238] (#1341931)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2016-103752d2a9

This update has been submitted for testing by myoung.

8 years ago

This update has obsoleted xen-4.5.3-7.fc23, and has inherited its bugs and notes.

8 years ago

This update has been pushed to testing.

8 years ago
User Icon cserpentis commented & provided feedback 8 years ago
karma

works for me

User Icon nathan95 commented & provided feedback 8 years ago
karma

no regression noted

This update has been submitted for stable by bodhi.

8 years ago
User Icon mhayden commented & provided feedback 8 years ago
karma

Works for me.

This update has been pushed to stable.

8 years ago

Please login to add feedback.

Metadata
Type
security
Karma
3
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
8 years ago
in testing
8 years ago
in stable
8 years ago
BZ#1335438 CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175)
0
0
BZ#1335442 CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178)
0
0
BZ#1336429 CVE-2016-4454 Qemu: display: vmsvga: out-of-bounds read in vmsvga_fifo_read_raw() routine
0
0
BZ#1336650 CVE-2016-4453 Qemu: display: vmsvga: infinite loop in vmsvga_fifo_run() routine
0
0
BZ#1340741 CVE-2016-4454 xen: Qemu: display: vmsvga: out-of-bounds read in vmsvga_fifo_read_raw() routine [fedora-all]
0
0
BZ#1340746 CVE-2016-4453 xen: Qemu: display: vmsvga: infinite loop in vmsvga_fifo_run() routine [fedora-all]
0
0
BZ#1341931 CVE-2016-5238 Qemu: scsi: esp: OOB write when using non-DMA mode in get_cmd
0
0
BZ#1342131 CVE-2016-4963 xsa178 xen: Unsanitised driver domain input in libxl device handling (XSA-178) [fedora-all]
0
0
BZ#1342132 CVE-2016-4962 xsa175 xen: Unsanitised guest input in libxl device handling code (XSA-175) [fedora-all]
0
0
BZ#1342529 CVE-2016-5242 xsa181 xen: arm: Host crash caused by VMID exhaustion (XSA-181)
0
0
BZ#1342530 xsa181 xen: arm: Host crash caused by VMID exhaustion (XSA-181) [fedora-all]
0
0
BZ#1343323 CVE-2016-5338 Qemu: scsi: esp: OOB r/w access while processing ESP_FIFO
0
0
BZ#1343909 CVE-2016-5337 Qemu: scsi: megasas: information leakage in megasas_ctrl_get_info
0
0

Automated Test Results