Thread: Xen issue XSA-108
-
09-30-2014, 12:32 PM #1
Xen issue XSA-108


Xen issue XSA-108
Hi John,
This is a short note to make you aware of the Xen security advisory XSA-108, which may have an impact on Xen hypervisors in SolusVM. It is not a SolusVM issue - it is an issue that affects many Xen environments.
What is the nature of the advisory?
Unfortunately we are under embargo. We cannot reveal specific details of the issue or patches at this time.
The embargo will be lifted at 1pm UK time on Wednesday 1st October.
If you are in a position to patch your Xen hypervisors now, we recommend you do so. Otherwise, we recommend that you prepare to patch your hypervisors as soon as possible after the embargo has lifted.
More information, coming soon
Keep watch on the Xen advisory site, where patches will be made available at 1pm on 1st October: http://xenbits.xen.org/xsa/. When the embargo has lifted we will publish a Knowledge Base article with details.
With thanks,
The SolusVM team

So Amazon gets first crack at this and the rest have to rush before a 0day hits? No more community aspect?Last edited by John_E; 09-30-2014 at 12:37 PM.
• Jetfire Networks LLC • Problem Solved.
• Consistent, Reliable, Masterful VPS Hosting Solutions
• Celebrating three years of growth based on quality before quantity.
• See the Internet through the eyes of our Looking Glass!
- Sponsored Links
-
09-30-2014, 01:08 PM #2
Yes, this has been out for a while now (not announced through SVM/OnApp though until recently). Looking forward to tomorrow.
Wow Technologies Inc.
Come visit our 18k sq ft. facility in Seattle!
Managed Private Cloud | Colocation | Disaster Recovery | Dedicated Servers
-
09-30-2014, 01:37 PM #3
I was reading about a few days back when they were trying to put off the security rumor, but people can see past the poker face. Especially when they have to cover their butts before the rest of the world, and still not disclose anything. Must be more than one, "we can't discuss the patches at this time".
Sounds plural to me.
**and omg that logo is huge, it wasn't that big when I threaded it... feel free to clean that up...• Jetfire Networks LLC • Problem Solved.
• Consistent, Reliable, Masterful VPS Hosting Solutions
• Celebrating three years of growth based on quality before quantity.
• See the Internet through the eyes of our Looking Glass!
-
09-30-2014, 01:45 PM #4
Evidently Linode has known for a while as well, or so I've been told.
• Jetfire Networks LLC • Problem Solved.
• Consistent, Reliable, Masterful VPS Hosting Solutions
• Celebrating three years of growth based on quality before quantity.
• See the Internet through the eyes of our Looking Glass!
- Sponsored Links
-
09-30-2014, 01:48 PM #5
Yes, there is a list of companies who already have disclosure including SolusVM themselves, Amazon, Linode, RedHat and others. Not sure how long they have known about it however.
Wow Technologies Inc.
Come visit our 18k sq ft. facility in Seattle!
Managed Private Cloud | Colocation | Disaster Recovery | Dedicated Servers
-
09-30-2014, 02:35 PM #6
Web Hosting Master
- Join Date
- Nov 2011
- Location
- Harrisburg, PA
- Posts
- 2,073
"We recommend that you patch Xen now."
"Patches will be released tomorrow."
Am I missing something here?
-
09-30-2014, 02:43 PM #7
Patches will be released publicly on Oct 1.
Organizations on the pre-disclosure list already have access to the patches www.xenproject.org/security-policy.htmlTranquil Hosting
-
09-30-2014, 03:29 PM #8
Web Hosting Master
- Join Date
- Nov 2011
- Location
- Harrisburg, PA
- Posts
- 2,073
-
10-01-2014, 02:55 AM #9
Web Hosting Master
- Join Date
- Jan 2008
- Posts
- 1,174
Just a quick question, if i am using Xen PV in SolusVM, how can I upgrade it to apply the patch (when it is released)?
|| Web Hosting Blog - Web Hosting security & latest web hosting industry Announcements
|| Web Hosting Discussion - A Web Hosting community
-
10-01-2014, 03:11 AM #10• Jetfire Networks LLC • Problem Solved.
• Consistent, Reliable, Masterful VPS Hosting Solutions
• Celebrating three years of growth based on quality before quantity.
• See the Internet through the eyes of our Looking Glass!
-
10-01-2014, 03:36 AM #11
Web Hosting Master
- Join Date
- Jan 2008
- Posts
- 1,174
|| Web Hosting Blog - Web Hosting security & latest web hosting industry Announcements
|| Web Hosting Discussion - A Web Hosting community
-
10-01-2014, 07:55 AM #12Dang not on the listSo the short version is "ouch".
and where would you get the updateIf you are in a position to patch your Xen hypervisors now, we recommend you do so
Centos XEN last update June 2014 and on xen project page 2 Sep█ Lowest Host/Empire Technology LLC
█ Offering Quality Shared, Reseller, VPS servers, and Dedicated Servers
█ 24x7 Tech Support http://empire-hosting.net
█ XEN Servers Now http://xenserversnow.com - Budget XEN VPS /
-
10-01-2014, 08:03 AM #13
Web Hosting Master
- Join Date
- Nov 2011
- Location
- Harrisburg, PA
- Posts
- 2,073
From the XSA:
Full details: http://xenbits.xen.org/xsa/advisory-108.htmlMITIGATION
==========
Running only PV guests will avoid this vulnerability.
Content, because their site is lagging bad for me:
Information
Advisory XSA-108
Public release 2014-10-01 12:00
Updated 2014-10-01 12:02
Version 4
CVE(s) CVE-2014-7188
Title Improper MSR range used for x2APIC emulation
Files
advisory-108.txt (signed advisory file)
xsa108.patch
Advisory
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Xen Security Advisory CVE-2014-7188 / XSA-108
version 4
Improper MSR range used for x2APIC emulation
UPDATES IN VERSION 4
====================
Public release.
ISSUE DESCRIPTION
=================
The MSR range specified for APIC use in the x2APIC access model spans
256 MSRs. Hypervisor code emulating read and write accesses to these
MSRs erroneously covered 1024 MSRs. While the write emulation path is
written such that accesses to the extra MSRs would not have any bad
effect (they end up being no-ops), the read path would (attempt to)
access memory beyond the single page set up for APIC emulation.
IMPACT
======
A buggy or malicious HVM guest can crash the host or read data
relating to other guests or the hypervisor itself.
VULNERABLE SYSTEMS
==================
Xen 4.1 and onward are vulnerable.
Only x86 systems are vulnerable. ARM systems are not vulnerable.
MITIGATION
==========
Running only PV guests will avoid this vulnerability.
CREDITS
=======
This issue was discovered Jan Beulich at SUSE.
RESOLUTION
==========
Applying the attached patch resolves this issue.
xsa108.patch xen-unstable, Xen 4.4.x, Xen 4.3.x, Xen 4.2.x
$ sha256sum xsa108*.patch
cf7ecf4b4680c09e8b1f03980d8350a0e1e7eb03060031788f972e0d4d47203e xsa108.patch
$
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQEcBAEBAgAGBQJUK+1fAAoJEIP+FMlX6CvZ6cwH+wdcnTCTdyAMc8bmQv+IxrMN
ue5rBYdX0b7CnnC2uCrwPssygna2cxTcVhJsU0eZk5OVrIU5rQ3PKtmFtxMwa3WS
my/vtyftTmoxAzftUKgpDFeicmZXlot3aowfRIiIc+GFZ59zAjDL2yQ0xMR1mJio
7SXl+dkcUPj5nXaeK1gFozJ8XNF+wArNQUPv0xUBIg4NSjQyqa7CMCZ5Q3IuJ53S
hKY37/MSoOViDORDPkeVr3BoSb7atYZSPwibqEUjeL5f+eXyVkbD0MkLQgu1ERtZ
p+dc+DTaRYm77LrDM+npZ+j1uSoVqdVzXtNYe6GZmbNRVXjbhJ+gJyJBcpy/a5Q=
=m0tK
-----END PGP SIGNATURE-----
Xenproject.org Security Team▐█▌Fresh Roasted Hosting :: High-performance Harrisburg web hosting since 2012!
▐█▌"The only thing better than the world's best customer service is never needing them in the first place."
▐█▌Shared :: VPS :: Reseller :: Dedicated :: Co-Location :: SSL Certificates
-
10-01-2014, 08:24 AM #14
Looks like they just updated it a few minutes ago
they made it seem like the sky was falling and it does not even affect us█ Lowest Host/Empire Technology LLC
█ Offering Quality Shared, Reseller, VPS servers, and Dedicated Servers
█ 24x7 Tech Support http://empire-hosting.net
█ XEN Servers Now http://xenserversnow.com - Budget XEN VPS /
-
10-01-2014, 08:31 AM #15
Web Hosting Guru
- Join Date
- Jun 2012
- Posts
- 328
Just a heads up regarding that link, the link in that post above (not the xen.org URL itself) is actually redirected. Yes, I am paranoid and I hate when security posts like that are redirected and tokenized through something I never heard of especially if it sounds like a bot-registered random domain I can't get info about on the first page of google...
-
10-01-2014, 09:02 AM #16
Junior Guru
- Join Date
- Oct 2012
- Posts
- 183
Does this effect my XenServer 6.1 64 bit servers?
-
10-01-2014, 10:56 AM #17
Web Hosting Master
- Join Date
- Oct 2005
- Location
- Summerville, SC
- Posts
- 911
I'm assuming it's just a tracking link for email purposes.
http://xenbits.xen.org/xsa/advisory-108.html
Is a direct link
-
10-01-2014, 11:05 AM #18
Quality Web Hosting Matters
- Join Date
- Sep 2006
- Location
- Servers
- Posts
- 1,587
Do this mean 64bit Xen hosts are not affected or they are ?
█ QHoster.com - Web Hosting with DDoS Protection | Shared & Reseller in Europe/North America
█ Linux/Windows RDP VPS 13 Locations : UK, US (5 states), Mexico, Canada, Bulgaria, Lithuania,
█ Italy, France, Germany,Netherlands, Switzerland, Rissia, Singapore | OpenVPN/PPTP Enabled
█ INSTANT | PayPal, Skrill, Payza, Bitcoin, WebMoney, Perfect Money, Ukash, CashU, paysafecard
-
10-01-2014, 11:10 AM #19
Randy
- Join Date
- Aug 2006
- Location
- Ashburn VA, San Diego CA
- Posts
- 4,524
Fast Serv Networks, LLC | AS29889 | Fully Managed Cloud, Streaming, Dedicated Servers, Colo by-the-U
Ashburn VA + San Diego CA Datacenters
-
10-01-2014, 11:11 AM #20
Aspiring Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 444
Citrix have got patches out for XenServer 6.0/6.1/6.2: http://support.citrix.com/article/CTX200218
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
10-01-2014, 11:13 AM #21
Quality Web Hosting Matters
- Join Date
- Sep 2006
- Location
- Servers
- Posts
- 1,587
What you mean all are 32 bit ? The Xen in installed on top of CentOS 64bit.
█ QHoster.com - Web Hosting with DDoS Protection | Shared & Reseller in Europe/North America
█ Linux/Windows RDP VPS 13 Locations : UK, US (5 states), Mexico, Canada, Bulgaria, Lithuania,
█ Italy, France, Germany,Netherlands, Switzerland, Rissia, Singapore | OpenVPN/PPTP Enabled
█ INSTANT | PayPal, Skrill, Payza, Bitcoin, WebMoney, Perfect Money, Ukash, CashU, paysafecard
-
10-01-2014, 11:14 AM #22
Aspiring Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 444
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
10-01-2014, 11:16 AM #23
Quality Web Hosting Matters
- Join Date
- Sep 2006
- Location
- Servers
- Posts
- 1,587
We are using normal Xen installed on CentOS 64bit. So the question was if this is affecting hosts like this ?
█ QHoster.com - Web Hosting with DDoS Protection | Shared & Reseller in Europe/North America
█ Linux/Windows RDP VPS 13 Locations : UK, US (5 states), Mexico, Canada, Bulgaria, Lithuania,
█ Italy, France, Germany,Netherlands, Switzerland, Rissia, Singapore | OpenVPN/PPTP Enabled
█ INSTANT | PayPal, Skrill, Payza, Bitcoin, WebMoney, Perfect Money, Ukash, CashU, paysafecard
-
10-01-2014, 11:20 AM #24
Aspiring Evangelist
- Join Date
- Aug 2007
- Location
- Lincoln, UK
- Posts
- 444
CentOS have pushed x86_64 patches for Xen4CentOS to fix XSA-108: http://lists.centos.org/pipermail/ce...er/020664.html
Freethought Internet Limited - Hosting, Servers and Connectivity
Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP. VAT number GB 987 0952 66.
-
10-01-2014, 12:57 PM #25• Jetfire Networks LLC • Problem Solved.
• Consistent, Reliable, Masterful VPS Hosting Solutions
• Celebrating three years of growth based on quality before quantity.
• See the Internet through the eyes of our Looking Glass!
Similar Threads
-
Xen time issue
By sniperscope in forum VPS HostingReplies: 26Last Post: 04-16-2012, 04:44 AM -
Xen VPS issue
By Gogg302 in forum Dedicated ServerReplies: 9Last Post: 01-31-2012, 05:54 PM -
R1Soft issue on Xen VM
By HarrySX in forum Hosting Software and Control PanelsReplies: 2Last Post: 04-02-2011, 08:47 AM -
Xen issue on node
By chetantech in forum VPS HostingReplies: 1Last Post: 11-04-2010, 01:32 PM -
Xen and the issue of swap
By hello-world in forum VPS HostingReplies: 8Last Post: 06-04-2007, 05:08 PM



Reply With Quote





