DSA-3390-1 xen -- security update

Related Vulnerabilities: CVE-2015-7835  

It was discovered that the code to validate level 2 page table entries is bypassed when certain conditions are satisfied. A malicious PV guest administrator can take advantage of this flaw to gain privileges via a crafted superpage mapping. For the oldstable distribution (wheezy), this problem has been fixed in version 4.1.4-3+deb7u9. For the stable distribution (jessie), this problem has been fixed in version 4.4.1-9+deb8u2. We recommend that you upgrade your xen packages.

Debian Security Advisory

DSA-3390-1 xen -- security update

Date Reported:
02 Nov 2015
Affected Packages:
xen
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-7835.
More information:

It was discovered that the code to validate level 2 page table entries is bypassed when certain conditions are satisfied. A malicious PV guest administrator can take advantage of this flaw to gain privileges via a crafted superpage mapping.

For the oldstable distribution (wheezy), this problem has been fixed in version 4.1.4-3+deb7u9.

For the stable distribution (jessie), this problem has been fixed in version 4.4.1-9+deb8u2.

We recommend that you upgrade your xen packages.