Live data from Hacker News

Five new undisclosed Xen vulnerabilities

xenbits.xen.org

1–10 of 50 posts

Re: Five new undisclosed Xen vulnerabilities

#5
post #2

Just received a message from Rackspace cloud regarding theses, it seems like they will have to reboot all instances. See https://community.rackspace.com/general/f/53/t/4978

See ya later uptime... 04:49:58 up 659 days

See ya later uptime... 04:49:58 up 659 days

your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/

Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188

http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...

Re: Five new undisclosed Xen vulnerabilities

#6
post #2

Just received a message from Rackspace cloud regarding theses, it seems like they will have to reboot all instances. See https://community.rackspace.com/general/f/53/t/4978

See ya later uptime... 04:49:58 up 659 days

Ouch! Might I ask what datacentre you're using?

Re: Five new undisclosed Xen vulnerabilities

#10
post #9
post #7

AWS uses xen too, right?

yes part of the reason I moved away from AWS years ago. Now it doesn't even matter since I am deploying to Docker anyways.

Good thing the host you run Docker on never needs to be patched or rebooted I guess?
Post reply on HN