Xen 'copy_to_user()' Local Security Bypass Vulnerability
BID:26954
Info
Xen 'copy_to_user()' Local Security Bypass Vulnerability
| Bugtraq ID: | 26954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6416 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 14 2007 12:00AM |
| Updated: | Jan 23 2008 07:58PM |
| Credit: | Alex Williamson discovered this issue. |
| Vulnerable: |
XenSource Xen 3.1.2 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server |
| Not Vulnerable: | |
Discussion
Xen 'copy_to_user()' Local Security Bypass Vulnerability
Xen is prone to a local security-bypass vulnerability that affects PAL emulation.
Local attackers can leverage this issue to access arbitrary memory regions from HVM guest systems. This could allow attackers to obtain potentially sensitive information that could aid in further attacks.
This issue affects Xen 3.1.2 on IA64 platforms; other versions may also be vulnerable.
Xen is prone to a local security-bypass vulnerability that affects PAL emulation.
Local attackers can leverage this issue to access arbitrary memory regions from HVM guest systems. This could allow attackers to obtain potentially sensitive information that could aid in further attacks.
This issue affects Xen 3.1.2 on IA64 platforms; other versions may also be vulnerable.
Exploit / POC
Xen 'copy_to_user()' Local Security Bypass Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xen 'copy_to_user()' Local Security Bypass Vulnerability
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
Solution:
Please see the referenced advisories for information on obtaining and applying the appropriate updates.
References
Xen 'copy_to_user()' Local Security Bypass Vulnerability
References:
References:
- [IA64] Fix vulnerability of copy_to_user in PAL emulation (Alex Williamson)
- Xen Project Homepage (Xen Project)
- RHSA-2008:0089-21 kernel security and bug fix update (Red Hat)