Steve's Blog

Xen 4.2.0 in testing & new kernel-xen package.

I’ve had a few emails asking about Xen 4.2.0. I’ve got a test version running and am monitoring it over the next few days. If it proves ok, I’ll push it to the repo.

In the meantime, yesterday I pushed a new kernel-xen package (3.5.4-2) which has the option for HPSA raid adapters enabled. This was an oversight originally and should mean that the kernel will boot properly on HP servers with this type of RAID card.

Xen packages 4.1.3-2 released.

Changes in this version:

  • Fri Sep 07 2012 Steven Haigh <netwiz @crc.id.au> - 4.1.3-2
  • XSA12 (CVE-2012-3494) - hypercall set_debugreg vulnerability
  • XSA13 (CVE-2012-3495) - hypercall physdev_get_free_pirq vulnerability
  • XSA14 (CVE-2012-3496) - XENMEM_populate_physmap DoS vulnerability
  • XSA16 (CVE-2012-3498) - PHYSDEVOP_map_pirq index vulnerability
  • XSA17 (CVE-2012-3515) - Qemu VT100 emulation vulnerability
  • XSA19 guest administrator can access qemu monitor console

Everyone should update to these packages ASAP.

Xen 4.1.3 RPMs available

Just finishing off the final touches to my Xen RPMs for version 4.1.3. Changes from the Xen release notes include:

Xen.org is pleased to announce the release of Xen 4.0.4 and 4.1.3.

These fix the following critical vulnerabilities:

  • CVE-2012-0217 / XSA-7: PV guest privilege escalation vulnerability
  • CVE-2012-0218 / XSA-8: guest denial of service on syscall/sysenter exception generation
  • CVE-2012-2934 / XSA-9: PV guest host Denial of Service
  • CVE-2012-3432 / XSA-10: HVM guest user mode MMIO emulation DoS vulnerability
  • CVE-2012-3433 / XSA-11: HVM guest destroy p2m teardown host DoS vulnerability

We recommend all users of the 4.0 and 4.1 stable series to update to these latest point releases.

Among many bug fixes and improvements (over 100 since Xen 4.1.2):

  • Updates for the latest Intel/AMD CPU revisions
  • Bug fixes and improvements to the libxl tool stack
  • Bug fixes for IOMMU handling (device passthrough to HVM guests)
  • Bug fixes for host kexec/kdump

NOTE: My previous 4.1.2 packages were already fixed for XSA-7, XSA-8, and XSA-9.

The new packages can be installed via yum - or if you’re a first time installer, you should follow the guide.