Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OXT-877 & OXT-878: Upgrade Xen and port latest XSAs. #496

Merged
merged 4 commits into from
Jan 23, 2017

Conversation

eric-ch
Copy link
Contributor

@eric-ch eric-ch commented Dec 22, 2016

Upgrade Xen to 4.6.4.
Port latest XSAs.

@eric-ch
Copy link
Contributor Author

eric-ch commented Dec 22, 2016

See openxt.git related PR: OpenXT/openxt#208

@eric-ch eric-ch changed the title OXT-877 & OXT-878 OXT-877 & OXT-878: Upgrade Xen and port latest XSAs. Dec 22, 2016
Eric Chanudet added 2 commits January 12, 2017 18:30
Upgrade to 4.6.4.

OXT-877

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
Port latest XSAs released in december 2016.

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>

OXT-878
@eric-ch
Copy link
Contributor Author

eric-ch commented Jan 12, 2017

Not yet rebased completely...

Eric Chanudet added 2 commits January 12, 2017 19:51
Libxl was ported on Xen 4.6.1 and merged while the PR for 4.6.4 was
created, so port the patch-queue on Xen 4.6.4.

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>

OXT-877
... to make the recipe more agnotic to versions.

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>

OXT-877
@eric-ch
Copy link
Contributor Author

eric-ch commented Jan 23, 2017

Build 241.
Images.

@jean-edouard
Copy link
Member

Testing now

@jean-edouard
Copy link
Member

LGTM, though the custom build doesn't include the new measured launch code.
Please rebase and rebuild.
Thanks

@jean-edouard
Copy link
Member

Built here: http://openxt-builder.ainfosec.com:8010/builders/openxt/builds/541
All good, merging soon.

@jean-edouard jean-edouard merged commit 785db29 into OpenXT:master Jan 23, 2017
@eric-ch eric-ch deleted the oxt-877-878 branch February 20, 2017 19:21
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Aug 25, 2017
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Aug 30, 2017
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Dec 5, 2017
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Jan 10, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Feb 26, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Mar 8, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Mar 13, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit that referenced this pull request Mar 20, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            #537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            #499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            #519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue #496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Mar 23, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
eric-ch pushed a commit to eric-ch/xenclient-oe that referenced this pull request Mar 23, 2018
See Change:
Release 2.2.0 Tue June 21 2016
        Security fixes:
            OpenXT#537  CVE-2016-0718 -- Fix crash on malformed input
                  CVE-2016-4472 -- Improve insufficient fix to CVE-2015-1283 /
                                   CVE-2015-2716 introduced with Expat 2.1.1
            OpenXT#499  CVE-2016-5300 -- Use more entropy for hash initialization
                                   than the original fix to CVE-2012-0876
            OpenXT#519  CVE-2012-6702 -- Resolve troublesome internal call to srand
                                   that was introduced with Expat 2.1.0
                                   when addressing CVE-2012-0876 (issue OpenXT#496)

Signed-off-by: Eric Chanudet <chanudete@ainfosec.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants