Ubuntu Security Notice USN-2849-1

Discussion in 'News Aggregator' started by Packet Storm, 21 Dec 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2849-1 - Felix Wilhelm discovered a race condition in the Xen paravirtualized drivers which can cause double fetch vulnerabilities. An attacker in the paravirtualized guest could exploit this flaw to cause a denial of service (crash the host) or potentially execute arbitrary code on the host. Konrad Rzeszutek Wilk discovered the Xen PCI backend driver does not perform sanity checks on the device's state. An attacker could exploit this flaw to cause a denial of service (NULL dereference) on the host. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...