Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDisrepancy in number of exploitable bugs in Xen #2480
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
andrewdavidwong
added
the
C: other
label
Dec 4, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
andrewdavidwong
added
the
C: doc
label
Dec 4, 2016
andrewdavidwong
added this to the
Documentation/website milestone
Dec 4, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
marmarek
Dec 4, 2016
Member
I'd keep that part in place. So - add a date. And maybe update the number anyway, like - "as of 2016, there has been only three publicly disclosed exploitable bug in the Xen"? Or keep the old number and add "as of Sep 2015"...
|
I'd keep that part in place. So - add a date. And maybe update the number anyway, like - "as of 2016, there has been only three publicly disclosed exploitable bug in the Xen"? Or keep the old number and add "as of Sep 2015"... |
andrewdavidwong
referenced this issue
in QubesOS/qubes-core-agent-linux
Dec 5, 2016
Merged
Update Xen bug count in sudoers comment #29
added a commit
to QubesOS/qubes-doc
that referenced
this issue
Dec 5, 2016
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
starius commentedDec 4, 2016
https://www.qubes-os.org/doc/vm-sudo/ says "so far there have been only one (!) publicly disclosed exploitable bug in the Xen hypervisor from a VM, found in 2008", but this seems to be outdated.
http://www.securityweek.com/xen-hypervisor-vulnerability-exposed-virtualized-servers tells about vulnerability CVE-2014-7188 forced the cloud to reboot many machines.
https://xenbits.xen.org/xsa/ lists hundreds of CVEs.