LWN.net Logo

xen: denial of service

Package(s):xen CVE #(s):CVE-2011-3346
Created:October 24, 2011 Updated:October 26, 2011
Description: A buffer overflow flaw was found in the Xen hypervisor SCSI subsystem emulation. An unprivileged, local guest user could provide a large number of bytes that are used to zero out a fixed-sized buffer via a SAI READ CAPACITY SCSI command, overwriting memory and causing the guest to crash.
Alerts:
Scientific Linux SL-xen-20111024 2011-10-24
Red Hat RHSA-2011:1401-01 2011-10-24
CentOS CESA-2011:1401 2011-10-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds