XEN Security Update XSA-185/186/187/188, CVE-2016-7092/7093/7094/7154
Issue | Summary | Affected Versions | Fixed | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Static Compute Resources | CloudBoot Compute Resources | Static Compute Resources | CloudBoot Compute Resources | ||||||
| CentOS 5.x | CentOS 6.x | CentOS 5.x | CentOS 6.x | CentOS 5.x | CentOS 6.x | CentOS 5.x | CentOS 6.x | ||
XSA-185/CVE-2016-7092 | Disallow L3 recurcive pagetable for 32-bit PV guests | ✓* | ✓* | ✓* | ✓* | ✓ | ✓ | ✓ | ✓ |
XSA-186/CVE-2016-7093 | Mishandling of instruction pointer truncation during emulation | - | - | - | - | - | - | - | - |
| XSA-187/CVE-2016-7094 | Overflow of SH_CTXT->SEG_REG[] | - | - | - | - | - | - | - | - |
| XSA-188/CVE-2016-7154 | Use after free in FIFO event channel code | - | ✓** | - | ✓** | - | ✓** | - | ✓** |
* Static and Cloudboot compute resources are affected and the compute resources running 32-bit guests are vulnerable.
** The issue affects only Static and CloudBoot compute resources running under CentOS 6.x with Xen 4.4.4 and OnApp version 4.2 and higher.
Static Compute Resources
For customers willing to upgrade to the latest compute resource tools (corresponding to OnApp version installed)
To eliminate the security issue for Static Compute Resources:
Run the OnApp Xen Compute Resource installer
1/onapp/onapp-hv-install/onapp-hv-xen-install.shReboot all compute resources.
For customers which are using latest compute resource tools or do not want to upgrade them:
CentOS 5.x
1# yum update xen xen-libsThis should update to the xen-3.4.4-24.el5.onapp.x86_64 version.
CentOS 6.x
1# yum update xen xen-hypervisor- For versions of OnApp HV tools prior to version 4.2.0 this should update to the xen-4.2.5-38.30.onapp.el6.x86_64 version.
- For versions of OnApp HV tools after version 4.2.0 the fix is provided by CentOS.org. The command above should update to the 4.4.4.-12 version.
Reboot all compute resources.
CloudBoot Compute resources
To eliminate the security issue for Cloudboot Compute Resources, see CloudBoot Compute Resources and CloudBoot Backup Server upgrade procedures. For more information on the update, refer to OnApp 5.0 Release Notes.
This should update to the following version:
CentOS 5.x | |||
|---|---|---|---|
| Xen |
|