From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([209.51.188.92]:37434) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gwkcJ-00056u-1O for qemu-devel@nongnu.org; Thu, 21 Feb 2019 04:26:08 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gwkcH-0004Dh-N0 for qemu-devel@nongnu.org; Thu, 21 Feb 2019 04:26:06 -0500 Date: Thu, 21 Feb 2019 09:25:46 +0000 From: Daniel =?utf-8?B?UC4gQmVycmFuZ8Op?= Message-ID: <20190221092546.GB17899@redhat.com> Reply-To: Daniel =?utf-8?B?UC4gQmVycmFuZ8Op?= References: <20190218181349.23885-1-ppandit@redhat.com> <20190219025500.GN9345@umbus.fritz.box> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20190219025500.GN9345@umbus.fritz.box> Content-Transfer-Encoding: quoted-printable Subject: Re: [Qemu-devel] [PATCH v4] ppc: add host-serial and host-model machine attributes List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: David Gibson Cc: P J P , QEMU Developers , qemu-ppc@nongnu.org, Greg Kurz , Prasad J Pandit On Tue, Feb 19, 2019 at 01:55:01PM +1100, David Gibson wrote: > On Mon, Feb 18, 2019 at 11:43:49PM +0530, P J P wrote: > > From: Prasad J Pandit > >=20 > > On ppc hosts, hypervisor shares following system attributes > >=20 > > - /proc/device-tree/system-id > > - /proc/device-tree/model > >=20 > > with a guest. This could lead to information leakage and misuse.[*] > > Add machine attributes to control such system information exposure > > to a guest. > >=20 > > [*] https://wiki.openstack.org/wiki/OSSN/OSSN-0028 > >=20 > > Reported-by: Daniel P. Berrang=C3=A9 > > Fix-suggested-by: Daniel P. Berrang=C3=A9 > > Signed-off-by: Prasad J Pandit >=20 > Applied to ppc-for-4.0, thanks. Could you add the word "CVE-2019-8934" to the commit message for this patch before sending a pulll request - either end of subject line, or just before the Reported-by line. Regards, Daniel --=20 |: https://berrange.com -o- https://www.flickr.com/photos/dberran= ge :| |: https://libvirt.org -o- https://fstop138.berrange.c= om :| |: https://entangle-photo.org -o- https://www.instagram.com/dberran= ge :|