Fedora 22 Security Update: xen-4.5.1-5.fc22

Resolved Bugs
1247142 – CVE-2015-5154 xen: qemu: ide: atapi: heap overflow during I/O buffer memory access [fedora-all]
1179352 – Utilize system-wide crypto-policies
1242246 – xen-qemu-dom0-disk-backend.service trys to run a non-existent executable
1243563 – CVE-2015-5154 qemu: ide: atapi: heap overflow during I/O buffer memory access
1239309 – xen package does not create new entry in /boot/efi/EFI/fedora/grub.cfg<br
QEMU heap overflow flaw while processing certain ATAPI commands.
[XSA-138, CVE-2015-5154] (#1247142)
try again to fix xen-qemu-dom0-disk-backend.service (#1242246)
correct qemu location in xen-qemu-dom0-disk-backend.service (#1242246),
rebuild efi grub.cfg if it is present (#1239309),
re-enable remus by building with libnl3,
modify gnutls use in line with Fedora’s crypto policies (#1179352)

Leave a Reply