qemu-ppc
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-ppc] [PATCH v4] ppc: add host-serial and host-model machine at


From: Daniel P . Berrangé
Subject: Re: [Qemu-ppc] [PATCH v4] ppc: add host-serial and host-model machine attributes
Date: Thu, 21 Feb 2019 09:25:46 +0000
User-agent: Mutt/1.10.1 (2018-07-13)

On Tue, Feb 19, 2019 at 01:55:01PM +1100, David Gibson wrote:
> On Mon, Feb 18, 2019 at 11:43:49PM +0530, P J P wrote:
> > From: Prasad J Pandit <address@hidden>
> > 
> > On ppc hosts, hypervisor shares following system attributes
> > 
> >   - /proc/device-tree/system-id
> >   - /proc/device-tree/model
> > 
> > with a guest. This could lead to information leakage and misuse.[*]
> > Add machine attributes to control such system information exposure
> > to a guest.
> > 
> > [*] https://wiki.openstack.org/wiki/OSSN/OSSN-0028
> > 
> > Reported-by: Daniel P. Berrangé <address@hidden>
> > Fix-suggested-by: Daniel P. Berrangé <address@hidden>
> > Signed-off-by: Prasad J Pandit <address@hidden>
> 
> Applied to ppc-for-4.0, thanks.

Could you add the word  "CVE-2019-8934" to the commit message for this
patch before sending a pulll request - either end of subject line, or
just before the Reported-by line.

Regards,
Daniel
-- 
|: https://berrange.com      -o-    https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org         -o-            https://fstop138.berrange.com :|
|: https://entangle-photo.org    -o-    https://www.instagram.com/dberrange :|



reply via email to

[Prev in Thread] Current Thread [Next in Thread]