From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steven Haigh Subject: Re: Xen Security Advisory 99 - unexpected pitfall in xenaccess API Date: Tue, 17 Jun 2014 23:24:52 +1000 Message-ID: <53A041A4.6050603@crc.id.au> References: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4798121655623042617==" Return-path: In-Reply-To: List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xen.org Errors-To: xen-devel-bounces@lists.xen.org To: Andres Lagar Cavilla , xen-devel@lists.xen.org, security@xen.org, xen-announce@lists.xen.org, oss-security@lists.openwall.com List-Id: xen-devel@lists.xenproject.org This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============4798121655623042617== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="dHxXBGmnJtEUSKFkBjEQqjg034SFmJ0qW" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --dHxXBGmnJtEUSKFkBjEQqjg034SFmJ0qW Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable On 17/06/14 23:13, Andres Lagar Cavilla wrote: > Xen Security Advisory XSA-99 > version 2 >=20 > unexpected pitfall in xenaccess API >=20 > UPDATES IN VERSION 2 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D >=20 > Public Release. >=20 > Added note regarding CVE. >=20 > ISSUE DESCRIPTION > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D >=20 > A test/example program, for exercising the Xen memaccess API, does not > take all necessary precautions against hostile guest behaviour. >=20 > As a result, software developers using it as an example or template > might have written and deployed vulnerable code. >=20 >> How? >=20 >> I've looked at the patch. It's the refactor proposed in a separate >> thread by Dushyant Behl, lifted up a level. Obviously useful, +2. >=20 >> But fundamentally, how is this a vulnerability? Since the dawn of time= >> guests can poke at the qemu and PV frontend rings. So self DoS, check.= >> But, privilege escalation? >=20 >> Is this predicated on the potential (lack of) software quality of the >> xenaccess backends? That's a fair argument, but a different story. >=20 >> I am puzzled how this is an XSA that addresses "privilege escalation".= Also note: [netwiz@dev xen-4.2.4]$ patch -p1 < ../xsa-99.patch patching file tools/libxc/xc_mem_access.c Hunk #1 succeeded at 24 with fuzz 2. patching file tools/libxc/xc_mem_event.c patching file tools/libxc/xenctrl.h Hunk #1 succeeded at 1907 (offset -116 lines). Hunk #2 succeeded at 1933 with fuzz 2 (offset -116 lines). patching file tools/tests/xen-access/xen-access.c Hunk #1 succeeded at 233 (offset 10 lines). Hunk #2 succeeded at 254 (offset 10 lines). Hunk #3 succeeded at 269 (offset 10 lines). Hunk #4 FAILED at 293. 1 out of 4 hunks FAILED -- saving rejects to file tools/tests/xen-access/xen-access.c.rej In a nutshell, it doesn't apply cleanly either... --=20 Steven Haigh Email: netwiz@crc.id.au Web: http://www.crc.id.au Phone: (03) 9001 6090 - 0412 935 897 Fax: (03) 8338 0299 --dHxXBGmnJtEUSKFkBjEQqjg034SFmJ0qW Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) iQIcBAEBAgAGBQJToEGkAAoJEEGvNdV6fTHcLBUQAKXEnVDSWotSd5FVZYEcw/us HYqZllorRNiV4qnD2hoSSNnSWNprKIhjGp9+HYIAMuW7+Ex5tE8hwq/zmQL7AqE6 R6f2BzJ2jUiry8szlwq2ZJJxp9y43yUAcYP0WEW4jNLAIIzzCn1+F6xp7lKFDYqh O1IcW28rv+YlFoEe+3BXtmxr9l4l6eK0Xv8MrtN0c6VoRmSbCW+xRj1rpUL7SL6r mi37tdCa9V/8iil7UPBQgE+O2ExfvkVKrXZWFojQaEs0Q4Z0orosmli4jVmOBuG6 NwOXc0rMUzSIWb5WruBDGcOMZEYCo4NPDBtgJ/OZIKzg0m8kLSQ8XZDq/RKj3iSo ls3Y31bywivH/YGBdUIq8RlNiSQ46serBl4O5ThF0dZR1raY9ckfl7TcrENoXI2q xQwrCnpZQD5k2w02HcRCtZZv1c5p4sVtHNbHdrQilsItPMYVcfkQXDNtWf1c37VR ZeE4R+MPPhmtJ1QjA7vsEMrn/Kyd3ZD3V61bPdmbH8f9bFRyGseYrvp7JoyzxCEX vJ5N1QbFWpPH936OkewJPwXD9imtwLWRlibAlGUpyjOIcWmWLySFnP0DQTZVF81d kSu4oG5Gxnf/mUX7MtNUKMBVJQFugYjfaqCA6H68AREZdngcxIsy9kyt8oTOL/vh ++YTMi59VzaflgAwpNLs =oL51 -----END PGP SIGNATURE----- --dHxXBGmnJtEUSKFkBjEQqjg034SFmJ0qW-- --===============4798121655623042617== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Xen-devel mailing list Xen-devel@lists.xen.org http://lists.xen.org/xen-devel --===============4798121655623042617==--