Debian Security Advisory
DSA-3847-1 xen -- security update
- Date Reported:
- 09 May 2017
- Affected Packages:
- xen
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-9932, CVE-2016-10013, CVE-2016-10024, CVE-2017-7228.
- More information:
-
Jan Beulich and Jann Horn discovered multiple vulnerabilities in the Xen hypervisor, which may lead to privilege escalation, guest-to-host breakout, denial of service or information leaks.
In additional to the CVE identifiers listed above, this update also addresses the vulnerabilities announced as XSA-213, XSA-214 and XSA-215.
For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u9.
For the upcoming stable distribution (stretch), these problems have been fixed in version 4.8.1-1+deb9u1.
For the unstable distribution (sid), these problems have been fixed in version 4.8.1-1+deb9u1.
We recommend that you upgrade your xen packages.