[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH v3] xen/tools: Introduce QNX IFS loader



On Tue, 2014-09-23 at 18:00 +0100, Ian Jackson wrote:
> Ian Campbell writes ("Re: [Xen-devel] [PATCH v3] xen/tools: Introduce QNX IFS 
> loader"):
> > On Tue, 2014-09-23 at 17:19 +0100, Ian Jackson wrote:
> > > These would all have been security bugs if the v3 patch had been
> > > accepted.  They would have been bugs that would potentially amount to
> > > privilege escalation for very many Xen installations.
> > 
> > Well, those booting untrusted QNX guests on ARM, which won't be many
> > yet, but point taken...
> 
> No.  The loader would run whenever it seems the appropriate image
> type, so everyone with it compiled in is vulnerable.

Yes, I realised this during dinner.

Ian.


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.