[Secure-testing-team] Bug#727100: domain doesn't reboot with xl toolstack

PASZTOR Gyorgy pasztor at linux.gyakg.u-szeged.hu
Tue Oct 22 09:52:02 UTC 2013


Package: xen-utils-4.1
Version: 4.1.4-3+deb7u1
Severity: important
Tags: security patch

When you use xl toolstack, you can't reboot domUs.
When you switch back to xm toolstack, than reboot works again.
I think the problem with the debian packaged version is the same as in
this thread:
http://lists.xen.org/archives/html/xen-devel/2011-09/msg01289.html
I also think it's a security issue, since this is kind of a DoS from
the viewpoint of a domU.
In that thread, Ian Campbel also provided a patch, which might work
for the debian version too. (I haven't tested yet.)

Cheers,
György PÁSZTOR

-- System Information:
Debian Release: 7.2
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=hu_HU.UTF-8, LC_CTYPE=hu_HU.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages xen-utils-4.1 depends on:
ii  e2fslibs          1.42.5-1.1
ii  libc6             2.13-38
ii  libgnutls26       2.12.20-7
ii  libncurses5       5.9-10
ii  libpci3           1:3.1.9-6
ii  libtinfo5         5.9-10
ii  libuuid1          2.20.1-5.3
ii  libxen-4.1        4.1.4-3+deb7u1
ii  libxenstore3.0    4.1.4-3+deb7u1
ii  python            2.7.3-4+deb7u1
ii  python2.7         2.7.3-6
ii  xen-utils-common  4.1.4-3+deb7u1
ii  zlib1g            1:1.2.7.dfsg-13

Versions of packages xen-utils-4.1 recommends:
ii  bridge-utils                                   1.5-6
ii  qemu-keymaps                                   1.1.2+dfsg-6a
ii  qemu-utils                                     1.1.2+dfsg-6a
ii  xen-hypervisor-4.1-amd64 [xen-hypervisor-4.1]  4.1.4-3+deb7u1

Versions of packages xen-utils-4.1 suggests:
pn  xen-docs-4.1  <none>

-- no debconf information
-------------- next part --------------
A non-text attachment was scrubbed...
Name: xl-migration-reboot.ian.patch
Type: text/x-diff
Size: 708 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20131022/e9fb0bfe/attachment.patch>


More information about the Secure-testing-team mailing list