All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steven Haigh <netwiz@crc.id.au>
To: Andres Lagar Cavilla <andres@lagarcavilla.org>,
	xen-devel@lists.xen.org, security@xen.org,
	xen-announce@lists.xen.org, oss-security@lists.openwall.com
Subject: Re: Xen Security Advisory 99 - unexpected pitfall in xenaccess API
Date: Tue, 17 Jun 2014 23:24:52 +1000	[thread overview]
Message-ID: <53A041A4.6050603@crc.id.au> (raw)
In-Reply-To: <CADzFZPtHf7jJGpiLa9vf9oM4-sf3t8z+TqK9_vxXKwqg_f4YVw@mail.gmail.com>


[-- Attachment #1.1: Type: text/plain, Size: 2025 bytes --]

On 17/06/14 23:13, Andres Lagar Cavilla wrote:
>                     Xen Security Advisory XSA-99
>                              version 2
> 
>                  unexpected pitfall in xenaccess API
> 
> UPDATES IN VERSION 2
> ====================
> 
> Public Release.
> 
> Added note regarding CVE.
> 
> ISSUE DESCRIPTION
> =================
> 
> A test/example program, for exercising the Xen memaccess API, does not
> take all necessary precautions against hostile guest behaviour.
> 
> As a result, software developers using it as an example or template
> might have written and deployed vulnerable code.
> 
>> How?
> 
>> I've looked at the patch. It's the refactor proposed in a separate
>> thread by Dushyant Behl, lifted up a level. Obviously useful, +2.
> 
>> But fundamentally, how is this a vulnerability? Since the dawn of time
>> guests can poke at the qemu and PV frontend rings. So self DoS, check.
>> But, privilege escalation?
> 
>> Is this predicated on the potential (lack of) software quality of the
>> xenaccess backends? That's a fair argument, but a different story.
> 
>> I am puzzled how this is an XSA that addresses "privilege escalation".

Also note:
[netwiz@dev xen-4.2.4]$ patch -p1 < ../xsa-99.patch
patching file tools/libxc/xc_mem_access.c
Hunk #1 succeeded at 24 with fuzz 2.
patching file tools/libxc/xc_mem_event.c
patching file tools/libxc/xenctrl.h
Hunk #1 succeeded at 1907 (offset -116 lines).
Hunk #2 succeeded at 1933 with fuzz 2 (offset -116 lines).
patching file tools/tests/xen-access/xen-access.c
Hunk #1 succeeded at 233 (offset 10 lines).
Hunk #2 succeeded at 254 (offset 10 lines).
Hunk #3 succeeded at 269 (offset 10 lines).
Hunk #4 FAILED at 293.
1 out of 4 hunks FAILED -- saving rejects to file
tools/tests/xen-access/xen-access.c.rej

In a nutshell, it doesn't apply cleanly either...

-- 
Steven Haigh

Email: netwiz@crc.id.au
Web: http://www.crc.id.au
Phone: (03) 9001 6090 - 0412 935 897
Fax: (03) 8338 0299


[-- Attachment #1.2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 836 bytes --]

[-- Attachment #2: Type: text/plain, Size: 126 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

  reply	other threads:[~2014-06-17 13:24 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-06-17 13:13 Xen Security Advisory 99 - unexpected pitfall in xenaccess API Andres Lagar Cavilla
2014-06-17 13:24 ` Steven Haigh [this message]
2014-06-17 13:40   ` Ian Campbell
     [not found]     ` <CAGU+autpif3iTpZ4BGNarXZksXAm37Owq5hmDTG++=aMBYaC9w@mail.gmail.com>
2014-06-17 18:23       ` Aravindh Puthiyaparambil (aravindp)
2014-06-17 13:36 ` Ian Campbell
     [not found] ` <1403012214.16844.111.camel@kazak.uk.xensource.com>
2014-06-17 13:50   ` Andres Lagar Cavilla
2014-06-17 13:57     ` Ian Campbell
2014-06-17 14:01       ` Andres Lagar Cavilla
  -- strict thread matches above, loose matches on Subject: below --
2014-06-17 12:16 Xen.org security team

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53A041A4.6050603@crc.id.au \
    --to=netwiz@crc.id.au \
    --cc=andres@lagarcavilla.org \
    --cc=oss-security@lists.openwall.com \
    --cc=security@xen.org \
    --cc=xen-announce@lists.xen.org \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.