Quotidien Shaarli

Tous les liens d'un jour sur une page.

August 9, 2015

Xen reports new guest-host escape, this time through CD-ROMs • The Register

The new vuln glories in the name XSA-138, aka CVE-2015-5154 and means “An HVM guest which has access to an emulated IDE CDROM device (e.g. with a device with "devtype=cdrom", or the "cdrom" convenience alias, in the VBD configuration) can exploit this vulnerability to take over the qemu process elevating its privilege to that of the qemu process.”