DSA-3847-1 xen -- security update

Related Vulnerabilities: CVE-2016-9932   CVE-2016-10013   CVE-2016-10024   CVE-2017-7228  

Jan Beulich and Jann Horn discovered multiple vulnerabilities in the Xen hypervisor, which may lead to privilege escalation, guest-to-host breakout, denial of service or information leaks. In additional to the CVE identifiers listed above, this update also addresses the vulnerabilities announced as XSA-213, XSA-214 and XSA-215. For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u9. For the upcoming stable distribution (stretch), these problems have been fixed in version 4.8.1-1+deb9u1. For the unstable distribution (sid), these problems have been fixed in version 4.8.1-1+deb9u1. We recommend that you upgrade your xen packages.

Debian Security Advisory

DSA-3847-1 xen -- security update

Date Reported:
09 May 2017
Affected Packages:
xen
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-9932, CVE-2016-10013, CVE-2016-10024, CVE-2017-7228.
More information:

Jan Beulich and Jann Horn discovered multiple vulnerabilities in the Xen hypervisor, which may lead to privilege escalation, guest-to-host breakout, denial of service or information leaks.

In additional to the CVE identifiers listed above, this update also addresses the vulnerabilities announced as XSA-213, XSA-214 and XSA-215.

For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u9.

For the upcoming stable distribution (stretch), these problems have been fixed in version 4.8.1-1+deb9u1.

For the unstable distribution (sid), these problems have been fixed in version 4.8.1-1+deb9u1.

We recommend that you upgrade your xen packages.