From mboxrd@z Thu Jan 1 00:00:00 1970 From: Keir Fraser Subject: Re: Xen 4.0.0x allows for data corruption in Dom0 Date: Sat, 06 Mar 2010 13:36:15 +0000 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xensource.com Errors-To: xen-devel-bounces@lists.xensource.com To: Joanna Rutkowska , "xen-devel@lists.xensource.com" List-Id: xen-devel@lists.xenproject.org On 06/03/2010 12:02, "Keir Fraser" wrote: > On 06/03/2010 10:12, "Joanna Rutkowska" > wrote: > >> It's really interesting how much control does the VM have over the data >> (and location) that are corrupted in Dom0 -- if it has any control, then >> it might allow for an interesting VM escape attack perhaps :) >> >> Unfortunately we don't have time to investigate this problem any further >> in our lab. > > Thanks, I'll see if I can repro with your simple setup. It's an interesting > one since presumably the domU is not doing much other waiting on its > rootdelay timeout when the corruption manifests. Sounds like the dom0 kernel > version doesn't matter at all? Tried a few times and no luck reproducing so far. I hope some other people on the list also will give it a go, since it's so easy to try it out. -- Keir