Live data from Hacker News

Five new undisclosed Xen vulnerabilities

xenbits.xen.org

11–20 of 50 posts

Re: Five new undisclosed Xen vulnerabilities

#11

Earlier quoted context omitted.

See ya later uptime... 04:49:58 up 659 days

See ya later uptime... 04:49:58 up 659 days your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/ Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...

Yeah. I had one server with over 900 days prior to Oct. It probably should have been rebooted for other reasons but thats the one that forced it.

Re: Five new undisclosed Xen vulnerabilities

#12
post #9

Earlier quoted context omitted.

yes part of the reason I moved away from AWS years ago. Now it doesn't even matter since I am deploying to Docker anyways.

Good thing the host you run Docker on never needs to be patched or rebooted I guess?

Yes, docker is immune to vulnerabilities because containers.

Re: Five new undisclosed Xen vulnerabilities

#14

Earlier quoted context omitted.

See ya later uptime... 04:49:58 up 659 days

See ya later uptime... 04:49:58 up 659 days your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/ Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...

That vulnerability only applies to HVM guests. No doubt there are other reasons to have rebooted since 2013, but if one of Rackspace's servers only has paravirtualized guests (do they use HVM at all? I don't know), they can get by without patching it.

Re: Five new undisclosed Xen vulnerabilities

#16

Earlier quoted context omitted.

See ya later uptime... 04:49:58 up 659 days your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/ Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...

That vulnerability only applies to HVM guests. No doubt there are other reasons to have rebooted since 2013, but if one of Rackspace's servers only has paravirtualized guests (do they use HVM at all? I don't know), they can get by without patching it.

[deleted]

Re: Five new undisclosed Xen vulnerabilities

#17

Earlier quoted context omitted.

See ya later uptime... 04:49:58 up 659 days your server is vulnerable to a number of Xen security vulnerabilities: http://xenbits.xen.org/xsa/ Including this one from Oct 1, 2014 that allows guests to read up to 3KB of memory from the hypervisor or other guests: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7188 http://threatpost.com/serious-hypervisor-bug-fix-causes-unex...

That vulnerability only applies to HVM guests. No doubt there are other reasons to have rebooted since 2013, but if one of Rackspace's servers only has paravirtualized guests (do they use HVM at all? I don't know), they can get by without patching it.

Did you see how many vulnerabilities 659 days covers? I mean, if that one doesn't apply, just go back a bit. How about this one from June 2014:

memory pages that were in use by the hypervisor and are eligible to be allocated to guests weren't being properly cleaned. Such exposure of information would happen through memory pages freshly allocated to or by the guest. ... it is possible for an attacker to obtain modest amounts of in-flight and in-use data, which might contain passwords or cryptographic keys.

http://xenbits.xen.org/xsa/advisory-100.html

Re: Five new undisclosed Xen vulnerabilities

#18
post #12

Earlier quoted context omitted.

Good thing the host you run Docker on never needs to be patched or rebooted I guess?

Yes, docker is immune to vulnerabilities because containers.

Not immune to human error:

https://medium.com/@fun_cuddles/docker-breakout-exploit-anal...

Re: Five new undisclosed Xen vulnerabilities

#19
post #7

AWS uses xen too, right?

There are a lot of vulnerabilities which don't affect them though -- either because the vulnerabilities are in specific features which EC2 doesn't use, or because Amazon is very conservative about which versions of Xen it uses and most vulnerabilities are in relatively new code.

I certainly hope Amazon will respond to these publicly, but I won't be very surprised if the response is "doesn't affect us".

Post reply on HN