Qubes Security Bulletin #24 (Critical bug)

149 views
Skip to first unread message

Joanna Rutkowska

unread,
Jul 26, 2016, 8:06:25 AM7/26/16
to qubes...@googlegroups.com, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Dear Qubes users,

We have just released a new Qubes Security Bulletin (QSB #24) for a critical bug
in the Xen hypervisor:

https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt

Please install the updates, immediately.

Regards,
joanna.

- --
The Qubes Security Team
https://qubes-os.org/doc/SecurityPage/
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJXl1I2AAoJEDOT2L8N3GcYL60QAKnMZVQxzY1mv56C02EU+s+i
ZoK6vvPEWqFjiFEBN7ojH6Xg8VDa73YMJhn7RAzqVbzdNauLTufjpXBuHtrQJ8oN
CtWCo9CIvRS8bNhl6IcKWh3/NORXRIRuBxceCVoMOvd8jHBZGQqbJYxeh6UzxFx+
0Cn6CAtofWBTnM6oV4/WXEMAVE/P3IW4zlui/kOHOwe/fpEt033b74ncq9DENkCU
CiaN/3p5Rgxa6nnIMQkQhSmP7HUJCzQXPLZ9DR1EcGHue3I8kZbikFcmDsLf5E9b
rSjRh0yhqUyQdNUIVaVQmIAaaCnkmuDKEw5RbiNmoFbyy73t5ktTNmfOSCN05hc3
xLeoNU6ZCTcWqmgkwCuCa8LdizDgd3FQnfCxj7injXRel6UKVROBhw8o16RG4oZm
G7k++g0K3hKyeF2YnZt4BQJbnuWW/JZ54fzP8m6YvfBBICj6ncKBBEV8XENCcCVL
tUOIZYieY9hUFowK6Gsb6Y9SFC2EJtNC9PY/xPc660txQHakQTgpZtN2uC4al6MV
pZonsQdG9O3csuHMOTIwKrRrmqt4LvCPz2EIYYHBlsAQU362/fR/4uE9MH87neRO
zWoSYBTBsZAq1JW9dNd+2YWABcWqijHbkcIxaQn/gFet9VSFBTqdeAmfJ3a7C08H
3wd6HMsUTKclNoSLYzF6
=bDeB
-----END PGP SIGNATURE-----

HW42

unread,
Jul 26, 2016, 8:26:01 AM7/26/16
to Joanna Rutkowska, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Joanna Rutkowska:
> Dear Qubes users,
>
> We have just released a new Qubes Security Bulletin (QSB #24) for a critical bug
> in the Xen hypervisor:
>
> https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt
>
> Please install the updates, immediately.

The updated Xen package seems to be missing on yum.qubes-os.org as well
as on the kernel.org mirror.
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXl1bKAAoJEOSsySeKZGgWJ6IP/ig3LK2WEb+5u6eXA70n9XNw
GyYk2pqY+W5CZhTivnwIKpRgKdOe2t4m2GDL5BhZeE9TMy3Kt4BOFnpVTyKqoB5P
77vJpP0A9tuo2OIxPhZIh37OmG7PgKWP8OYiUWuv32S9n9e+bULDwQWEyWVX/+Zk
AEjZ2BXi5g4Uj3kHBSeH/VOKcxJ8R+/Sqf4t+TIG0otLc1YvzF6OPlsYrQwfUP6I
dxFDoZTrO16DrvGYGd/K55UyeJgvfZwmfSxtSvn5bTEsFkNZJkdcPdcm3ErkWdIK
V/yk/faTzeJRHkw8UidO6sWUo2wRe4IALOTXTqs9UMfnuPHu0EkA5C07LMgwzJ9G
HuxsE6yqzRiANEZPnHrEoMY1IAh+dVqAMz/ju0EpomGGiZ/I+qYR0+bLuvgFzpP6
8Fy6SyCEuuymrw/5Nku4JaAuD5TmyU8NAHGuyQMi8kCpLzCNaeWQo2vp4OSkOcgI
eBWDi2bkswIR9MPksMYcwLH9Sy9MxIqKhImiPgHfoYDWVP8OrZGoUaaSvJyH0mP+
ExilutcGf67jgBdOmsDBkpzxiczWuz4+lZWYJmD6tqoPlGo8YfWKtTgGXDL7OZas
9TTYERG43wmW3YRjZ/OLTnV1OlylLltMrPDbBhLD86OTAesM21qEntkpgrHatane
/A2oTMY4onIOm+gyavnu
=tUEt
-----END PGP SIGNATURE-----

Marek Marczykowski-Górecki

unread,
Jul 26, 2016, 8:30:45 AM7/26/16
to HW42, Joanna Rutkowska, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Tue, Jul 26, 2016 at 12:25:00PM +0000, HW42 wrote:
> Joanna Rutkowska:
> > Dear Qubes users,
> >
> > We have just released a new Qubes Security Bulletin (QSB #24) for a critical bug
> > in the Xen hypervisor:
> >
> > https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt
> >
> > Please install the updates, immediately.
>
> The updated Xen package seems to be missing on yum.qubes-os.org as well
> as on the kernel.org mirror.

kernel.org sync is started once a day. But main repository is at
yum.qubes-os.org and packages are there:
http://yum.qubes-os.org/r3.0/current/dom0/fc20/rpm/xen-4.4.3-12.fc20.x86_64.rpm
http://yum.qubes-os.org/r3.1/current/dom0/fc20/rpm/xen-4.6.1-20.fc20.x86_64.rpm
http://yum.qubes-os.org/r3.2/current/dom0/fc23/rpm/xen-4.6.1-20.fc23.x86_64.rpm

You may need to call qubes-dom0-update --clean if you have cached old
metadata.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJXl1fvAAoJENuP0xzK19csadsIAJHeaLq8hUvXEGbA6+FzDzf8
0cVQjUHKF3DWLRg6jb3KYXgosNfK3nfFsd4HF0MTHZ4/7gVOAva1mjqEcyDrxJgf
ZsHt7jGP0R80jUgRhqGrTQ1jPAh+D2Y/8mMrUlcwBSjJEG3BJskK/gzkgWIFr2i9
1hjmnzv8Sa9AKD1VPZl11xhUEcNjVSP7bgay3AME8YCIseuUdrcs7j9O8I368sAk
RGGLLwVB9Or9hb3EiopH18G/Q8dFew69o/x/I2++CCcIbyyFKk8N1m5UPN1x9Nme
HX2Hj+FQcZA9Vi/pSc7meWX9JKOc5GNUdFuv9qIRpEJSCHrOo7v1vJDYI+w7sbU=
=NTm5
-----END PGP SIGNATURE-----

HW42

unread,
Jul 26, 2016, 8:46:47 AM7/26/16
to Marek Marczykowski-Górecki, Joanna Rutkowska, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Marek Marczykowski-Górecki:
> On Tue, Jul 26, 2016 at 12:25:00PM +0000, HW42 wrote:
>> Joanna Rutkowska:
>>> Dear Qubes users,
>>>
>>> We have just released a new Qubes Security Bulletin (QSB #24) for a critical bug
>>> in the Xen hypervisor:
>>>
>>> https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt
>>>
>>> Please install the updates, immediately.
>
>> The updated Xen package seems to be missing on yum.qubes-os.org as well
>> as on the kernel.org mirror.
>
> kernel.org sync is started once a day. But main repository is at
> yum.qubes-os.org and packages are there:
> http://yum.qubes-os.org/r3.0/current/dom0/fc20/rpm/xen-4.4.3-12.fc20.x86_64.rpm
> http://yum.qubes-os.org/r3.1/current/dom0/fc20/rpm/xen-4.6.1-20.fc20.x86_64.rpm
> http://yum.qubes-os.org/r3.2/current/dom0/fc23/rpm/xen-4.6.1-20.fc23.x86_64.rpm

When I wrote the mail I checked with a browser and the files were not
listed on the index page . About five minutes later I refreshed the page
and they were there.

> You may need to call qubes-dom0-update --clean if you have cached old
> metadata.
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXl1uvAAoJEOSsySeKZGgWOcgP/RSP+ynfCQAeYbI89x5Ju1BJ
e0jb1LswKJh6t4P+omSWfHVVlBKn4SiEiHf+sz90xvHyg9Q0YdJjc6A0genIhc2I
W7j0PbTm+Uaoh9Vf16mbMxe0eT2DProNeNIy1Q1BoJOHpHfI2erhtru/WtocOQHE
w+ymLI9kL0S7CGYcvFuVRmp3uNBHDXIV7xH44fdCSvCTNKCIsNXAwqB3sFth/PHF
r2HNhjVLPwR3ExcjiyuS7xGESebTTxM11hH90+jOvXLbfPMcwgZoIIrVbGie320u
ZkCyACAT0X9bIoNzEY6u8V6YM7pImlDiG7bFkAFRYmNZDTnPIuDt/+boqCD30SYa
FYB2vSF69pQNPMzYRW26pr/UXGgSM7PhPoP8OolngcYh2voeH1tdi5P7AI8D1KpL
aznNh3WwcCGC+ZyUmQQuOaC8/TgHqAE8pum9rR5+583RIHZGsNYw0BygFckZb9Op
iNCg5i0waRBSF21zRjQhTtfaofpFdLUZHPPRRIRV+o20A6IyK8WmhC23PiKr6nmT
jM4g0OImXHWdD9jMNvR8+/Rxm2BjECZuNTcHlfAE75/grmOj9nwbdStNO3eaiOzc
ABJjTGabjDJdfRpx1w+L6hiXmhyxWyR8LU9qfWru/34wQj9TTxfs7zz51YRmcpIK
eGt2F23HUAQnOoWgJ9v4
=YUw/
-----END PGP SIGNATURE-----

Konstantin Ryabitsev

unread,
Jul 26, 2016, 9:12:08 AM7/26/16
to Marek Marczykowski-Górecki, HW42, Joanna Rutkowska, qubes...@googlegroups.com
On Tue, Jul 26, 2016 at 02:30:36PM +0200, Marek Marczykowski-Górecki wrote:
> kernel.org sync is started once a day

We can do it more frequently if you like -- I believe the concern was
hitting your master mirror with too much force. Current runs are done at
22:45 UTC daily and we can do it as frequently as once an hour if you
need.

Regards,
--
Konstantin Ryabitsev
Linux Foundation Collab Projects
Montréal, Québec
signature.asc

Marek Marczykowski-Górecki

unread,
Jul 26, 2016, 12:02:18 PM7/26/16
to HW42, Joanna Rutkowska, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Tue, Jul 26, 2016 at 09:12:04AM -0400, Konstantin Ryabitsev wrote:
> On Tue, Jul 26, 2016 at 02:30:36PM +0200, Marek Marczykowski-Górecki wrote:
> > kernel.org sync is started once a day
>
> We can do it more frequently if you like -- I believe the concern was
> hitting your master mirror with too much force. Current runs are done at
> 22:45 UTC daily and we can do it as frequently as once an hour if you
> need.

For ordinary updates once a day is ok. And for security updates it don't
worth changing, because those are not so big/frequent.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJXl4l+AAoJENuP0xzK19csfdEH/ArKeupYbvlXxNKoKfTdLpYH
YgB4iu/yNRVeIkhaVJBDp3i3a2Awr6SEs/mcdYWjVvwAX2F0HTc1fv/VTlg2+9ui
sX6P9kvNhx4RVQiBYUEwxp5xruD/hFF/NQvY9gksiXYYF1cndzitfHwN3wx4Zt8O
bojy7PYZWbC/S/WPmlzEZlEfvJNK6fVpv9OQJu/l/7fbKk9BgczmEDkwekG62TZC
4Am1ITqHA/TIQ3Z1UvsTYcgqNslyqSxU2FVTzdGsrozNEX8I0wgnV6l0lgeYTqZm
d5q1ojgSn7ffvFo+cE4QgBOg7+gJ4MroLeKLgHCnbKtRhQYJf02gjkVfSer5jPQ=
=dczW
-----END PGP SIGNATURE-----

Christophe Brocas

unread,
Aug 5, 2016, 3:47:15 AM8/5/16
to qubes...@googlegroups.com
Le 26/07/2016 14:06, Joanna Rutkowska a écrit :
> Dear Qubes users,
>
> We have just released a new Qubes Security Bulletin (QSB #24) for a critical bug
> in the Xen hypervisor:
>
> https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-024-2016.txt
>
> Please install the updates, immediately.
>
> Regards,
> joanna.
To illustrate, a blogpost about the exploitation of this Xen bug by the original
reporter, Jérémie Boutoille from Quarkslab.

http://blog.quarkslab.com/xen-exploitation-part-3-xsa-182-qubes-escape.html

Cheers
Christophe


*****************************************************
"Le contenu de ce courriel et ses eventuelles pièces jointes sont confidentiels. Ils s'adressent exclusivement à la personne destinataire. Si cet envoi ne vous est pas destiné, ou si vous l'avez reçu par erreur, et afin de ne pas violer le secret des correspondances, vous ne devez pas le transmettre à d'autres personnes ni le reproduire. Merci de le renvoyer à l'émetteur et de le détruire.

Attention : L'Organisme de l'émetteur du message ne pourra être tenu responsable de l'altération du présent courriel. Il appartient au destinataire de vérifier que les messages et pièces jointes reçus ne contiennent pas de virus. Les opinions contenues dans ce courriel et ses éventuelles pièces jointes sont celles de l'émetteur. Elles ne reflètent pas la position de l'Organisme sauf s'il en est disposé autrement dans le présent courriel."
******************************************************

signature.asc
Reply all
Reply to author
Forward
0 new messages