XSA-2

CVE-2011-1583


问题描述

xsa2

paravirtualised kernel image validation

The functions which interpret the kernel image supplied for a paravirtualised guest, and decompress it into memory when booting the domain, are incautious. Specifically:

integer overflow, lack of check (error check)


Patch描述

http://xenbits.xen.org/hg/xen-4.1-testing.hg/rev/e2e575f8b5d9

libxc: [CVE-2011-1583] pv kernel image validation

The functions which interpret the kernel image supplied for a paravirtualised guest, and decompress it into memory when booting the domain, are incautious. Specifically:


Consequence

An attacker who can supply a kernel image to be booted as a paravirtualised guest might be able to:

privilege escalation, information leak, DoS