Bug 6931 - xen new security issues CVE-2012-2625 and CVE-2012-3432
Summary: xen new security issues CVE-2012-2625 and CVE-2012-3432
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 2
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: AL13N
QA Contact: Sec team
URL: https://wiki.mageia.org/en/XenCVE
Whiteboard:
Keywords:
Depends on: 10586
Blocks:
  Show dependency treegraph
 
Reported: 2012-08-01 23:13 CEST by David Walser
Modified: 2013-11-22 15:54 CET (History)
5 users (show)

See Also:
Source RPM: xen-4.1.2-4.mga2.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2012-08-01 23:13:17 CEST
RedHat has issued an advisory on July 31:
https://rhn.redhat.com/errata/RHSA-2012-1130.html
David Walser 2012-08-01 23:13:47 CEST

CC: (none) => alien
Whiteboard: (none) => MGA2TOO, MGA1TOO

David Walser 2012-08-01 23:13:54 CEST

CC: (none) => tmb

David Walser 2012-08-01 23:14:05 CEST

CC: (none) => thierry.vignaud

David Walser 2012-08-01 23:14:14 CEST

CC: (none) => guillomovitch

Comment 1 David Walser 2012-08-01 23:24:18 CEST
This was addressed by Fedora on June 14:
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082824.html

That advisory also lists CVE-2012-0217, CVE-2012-0218, and CVE-2012-2934 which may also be relevant.  Those CVEs are also listed in these advisories:
http://www.debian.org/security/2012/dsa-2501 Debian, June 24
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00008.html SuSE, June 12
http://lists.opensuse.org/opensuse-security-announce/2012-07/msg00008.html OpenSuSE, July 18

from http://lwn.net/Vulnerabilities/501763/
Comment 2 AL13N 2012-08-02 11:55:58 CEST
submitted xen-4.1.2-4.1.mga2 and xen-4.1.0-2.1.mga1

( xen-4.1.2-6.mga3 fails due to new GCC, but that shouldn't hold off this bug, since it's cauldron )

i'm afraid this is the limit of what i have time for atm (i'm on holiday)
Comment 3 David Walser 2012-08-02 14:48:43 CEST
That's weird, the build log doesn't even say what the error was.
Comment 4 David Walser 2012-08-02 14:57:41 CEST
Oh I guess it's the incompatible pointer types in i8259.c that's throwing it off.
Comment 5 David Walser 2012-08-02 15:01:05 CEST
Packages built for updates:
xen-4.1.0-2.1.mga1
xen-ocaml-4.1.0-2.1.mga1
xen-hypervisor-4.1.0-2.1.mga1
xen-doc-4.1.0-2.1.mga1
libxen3.0-4.1.0-2.1.mga1
libxen-devel-4.1.0-2.1.mga1
xen-4.1.2-4.1.mga2
ocaml-xen-4.1.2-4.1.mga2
xen-hypervisor-4.1.2-4.1.mga2
xen-doc-4.1.2-4.1.mga2
libxen3.0-4.1.2-4.1.mga2
libxen-devel-4.1.2-4.1.mga2
Comment 6 David Walser 2012-08-06 21:01:08 CEST
Now there's another one, CVE-2012-3432.

Fedora has issued an advisory on July 27:
http://lists.fedoraproject.org/pipermail/package-announce/2012-August/084648.html

from http://lwn.net/Vulnerabilities/509939/

Summary: xen new security issue CVE-2012-2625 => xen new security issues CVE-2012-2625 and CVE-2012-3432

Comment 7 David Walser 2012-08-11 20:02:12 CEST
I found some older ones that we missed as well.

CVE-2011-3262
http://lwn.net/Vulnerabilities/466206/

CVE-2011-1898 (should only affect Mageia 1)
http://lwn.net/Vulnerabilities/449904/

CVE-2011-1583
http://lwn.net/Vulnerabilities/442081/
Comment 8 David Walser 2012-08-11 20:20:00 CEST
Some more possible ones.

CVE-2011-3346
http://lwn.net/Vulnerabilities/464289/

CVE-2011-2901
http://lwn.net/Vulnerabilities/457392/

CVE-2011-3131
http://lwn.net/Vulnerabilities/457108/
Comment 9 AL13N 2012-08-12 21:58:12 CEST
:(

...

Since xen is likely not-working on mga1, i'd like to drop support for it... really, i don't think anyone is using xen on mga1, if somone can, then i'd like to know the magic involved...

for the other CVE's... i'm thinking of waiting some more just to see if more of these CVE's are going to appear...
Comment 10 David Walser 2012-08-20 18:49:50 CEST
Debian has issued an advisory on August 18:
http://www.debian.org/security/2012/dsa-2531

This covers CVE-2012-3432 (mentioned in Comment 6) and CVE-2012-3433 (not previously mentioned).
Comment 11 AL13N 2012-08-20 19:12:09 CEST
so to summate: (i hope i'm not missing something)?

CVE-2012-2625
(patched)

CVE-2012-0217
(patched)

CVE-2012-0218
(patched)

CVE-2012-2934
(patched)

CVE-2011-3262
http://lwn.net/Vulnerabilities/466206/

CVE-2011-1898 (should only affect Mageia 1)
http://lwn.net/Vulnerabilities/449904/

CVE-2011-1583
http://lwn.net/Vulnerabilities/442081/

CVE-2011-3346
http://lwn.net/Vulnerabilities/464289/

CVE-2011-2901
http://lwn.net/Vulnerabilities/457392/

CVE-2011-3131
http://lwn.net/Vulnerabilities/457108/

CVE-2012-3432 + CVE-2012-3433
see http://www.debian.org/security/2012/dsa-2531 for patch
Comment 12 David Walser 2012-08-20 19:58:54 CEST
Yep.  With CVE-2011-3346, CVE-2011-2901, and CVE-2011-3131, I'm not 100% sure we're affected by those, as I don't know which versions are vulnerable.  The other ones should all affect us.
Comment 13 Guillaume Rousse 2012-08-23 10:43:23 CEST
I just updated xen to 4.1.3 in cauldron. Here's an updated summary:
CVE-2012-3433: no patch found in debian for 4.1.3, so likely to be fixed
CVE-2012-3432: no patch found in debian for 4.1.3, so likely to be fixed
CVE-2012-2934: fixed in 4.1.3
CVE-2012-2625: no detail given
CVE-2012-0218: fixed in 4.1.3
CVE-2012-0217: fixed in 4.1.3
CVE-2011-3346: no patch found in fedora for 4.1.3, so likely to be fixed
CVE-2011-3262: no patch found in debian for 4.1.3, so likely to be fixed
CVE-2011-3131: no patch found in fedora for 4.1.3, so likely to be fixed
CVE-2011-2901: no patch found in fedora for 4.1.3, so likely to be fixed
CVE-2011-1898: fixed in 4.1.3
CVE-2011-1583: no patch found in fedora for 4.1.3, so likely to be fixed

So it seems the problem is fixed for cauldron, as least.
Comment 14 David Walser 2012-09-05 21:42:55 CEST
CVE-2012-3515:
https://rhn.redhat.com/errata/RHSA-2012-1236.html
Comment 15 David Walser 2012-09-08 03:31:37 CEST
CVE-2012-3494 CVE-2012-3495 CVE-2012-3496 CVE-2012-3498 CVE-2012-3516:
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00004.html
David Walser 2012-10-10 00:48:25 CEST

CC: (none) => oe

Comment 18 David Walser 2012-11-16 19:22:37 CET
CVE-2012-3497 CVE-2012-4535 CVE-2012-4536 CVE-2012-4537 CVE-2012-4538 CVE-2012-4539:
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00008.html

from http://lwn.net/Vulnerabilities/525449/
Comment 19 David Walser 2012-12-07 00:35:27 CET
CVE-2012-5510 CVE-2012-5511 CVE-2012-5512 CVE-2012-5513 CVE-2012-5514 CVE-2012-5515:
http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00001.html

from http://lwn.net/Vulnerabilities/528316/
Comment 20 AL13N 2013-01-08 23:07:03 CET
i just submitted xen-4.2.1-1.mga3, i had to remove quite some patches (also security ones)

i do hope that alot of these are fixed upstream, and i guess i should check all of them, but it's a lot...

maybe a wiki page detailing these would be better...
Comment 21 AL13N 2013-01-09 00:11:34 CET
https://wiki.mageia.org/en/XenCVE

URL: http://lwn.net/Vulnerabilities/509167/ => https://wiki.mageia.org/en/XenCVE

Comment 22 David Walser 2013-01-09 00:46:49 CET
Original bug report URL was:
http://lwn.net/Vulnerabilities/509167/

Not mentioned anywhere else, so saving for reference.
Comment 24 AL13N 2013-01-24 00:11:22 CET
for now updated the table for completeness.

given the xen lack of testing, i'm holding off on this a bit. i do have received hardware for me to test xen on. i'm gonna start with these after i got it tested.
Comment 25 David Walser 2013-02-05 18:50:45 CET
CVE-2013-0151 CVE-2013-0152
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098106.html

from http://lwn.net/Vulnerabilities/536058/


It's also worth pointing out that xen has been affected bysome of the CVEs that we fixed in qemu over the past year, but they may not all be listed in this bug.  The CVE-2012-6075 (which we recently fixed in qemu), also mentioned in the above Fedora advisory, is one example.
Comment 28 AL13N 2013-04-17 23:42:51 CEST
switching to mga2 for now, since cauldron is patched...

Version: Cauldron => 2
Whiteboard: MGA2TOO, MGA1TOO => (none)

AL13N 2013-04-17 23:43:11 CEST

Hardware: i586 => All

Comment 29 David Walser 2013-04-18 15:24:41 CEST
LWN link for CVE-2013-1920 changed for some reason.

http://lwn.net/Vulnerabilities/547595/
Comment 30 David Walser 2013-04-18 21:30:25 CEST
CVE-2013-1917 CVE-2013-1919
http://www.debian.org/security/2013/dsa-2662

from http://lwn.net/Vulnerabilities/547772/
Comment 32 David Walser 2013-05-13 20:27:12 CEST
CVE-2013-1918 CVE-2013-1952
http://www.debian.org/security/2013/dsa-2666

from http://lwn.net/Vulnerabilities/550448/

Version: 2 => Cauldron
Whiteboard: (none) => MGA3TOO, MGA2TOO

Comment 33 AL13N 2013-05-13 21:23:39 CEST
David; didn't those get fixed in mga3/cauldron?
Comment 34 David Walser 2013-05-13 21:49:30 CEST
(In reply to AL13N from comment #33)
> David; didn't those get fixed in mga3/cauldron?

Whoops, sorry!  Thanks.

Version: Cauldron => 2
Whiteboard: MGA3TOO, MGA2TOO => (none)

Comment 36 David Walser 2013-06-14 17:55:22 CEST
CVE-2013-2076 CVE-2013-2077 CVE-2013-2078
https://lists.fedoraproject.org/pipermail/package-announce/2013-June/108918.html

from http://lwn.net/Vulnerabilities/554419/
David Walser 2013-06-21 22:27:14 CEST

Depends on: (none) => 10586

Comment 37 David Walser 2013-06-24 20:01:31 CEST
CVE-2013-2194 CVE-2013-2195 CVE-2013-2196
https://lists.fedoraproject.org/pipermail/package-announce/2013-June/109711.html

from http://lwn.net/Vulnerabilities/556152/
Comment 38 David Walser 2013-07-02 23:54:38 CEST
CVE-2013-2211 CVE-2013-1432
http://advisories.mageia.org/MGASA-2013-0197.html

from http://lwn.net/Vulnerabilities/557259/
David Walser 2013-08-27 16:52:56 CEST

Assignee: bugsquad => alien

Comment 42 AL13N 2013-10-10 20:25:00 CEST
submitted xen-4.2.1-17.2.mga3 with new CVE fixes: CVE-2013-4329, CVE-2013-1442, CVE-2013-4355, CVE-2013-4361, CVE-2013-4368, CVE-2013-4369, CVE-2013-4370, CVE-2013-4371, CVE-2013-4375

cauldron follows soon with extra CVE-2013-4356

mga2 will follow at a later time
Comment 43 David Walser 2013-10-10 20:27:00 CEST
Cool.  I've kept this bug around for Mageia 2, so when you're ready, please file a new bug for the Mageia 3 update, with an advisory.  Thanks!
Comment 44 AL13N 2013-10-10 22:53:48 CEST
oh nuts... i figured you'd use this one for both Mga2 and Mga3...

in the main time it looks like the cauldron one is finally working...
Comment 46 David Walser 2013-10-23 18:45:22 CEST
CVE-2013-4369 CVE-2013-4370 CVE-2013-4371 CVE-2013-4375
https://lists.fedoraproject.org/pipermail/package-announce/2013-October/119531.html

from http://lwn.net/Vulnerabilities/571442/
Comment 50 David Walser 2013-11-22 15:54:52 CET
Closing this now due to Mageia 2 EOL.

http://blog.mageia.org/en/2013/11/21/farewell-mageia-2/

Please file new bugs for any future Mageia 3 (or later) xen updates.

Status: NEW => RESOLVED
Resolution: (none) => OLD
QA Contact: (none) => security


Note You need to log in before you can comment on or make changes to this bug.