Re: CVE triage for Xen

2017-01-04 Thread Guido Günther
Hi Hugo, On Wed, Jan 04, 2017 at 10:12:44AM +0100, Hugo Lefeuvre wrote: > Hi Guido, > > > See https://wiki.xenproject.org/wiki/QEMU_Upstream . It's only used for > > device emulation so bugs in e.g. TCG or KVM are not affecting XEN. Also > > all devices not available on i386 / amd64 can be ignored

Re: CVE triage for Xen

2017-01-04 Thread Hugo Lefeuvre
Hi Guido, > See https://wiki.xenproject.org/wiki/QEMU_Upstream . It's only used for > device emulation so bugs in e.g. TCG or KVM are not affecting XEN. Also > all devices not available on i386 / amd64 can be ignored. That should > already cut down the list considerably. Thanks for the advice. So

Re: CVE triage for Xen

2016-12-28 Thread Guido Günther
Hi Hugo, On Wed, Dec 28, 2016 at 12:03:48AM +0100, Hugo Lefeuvre wrote: > Hi, > > Last month I've gone through most of the CVEs affecting qemu in the > past years and investigated whether they were likely to affect the > wheezy version of Xen. For that I have considered that any > vulnerability af

CVE triage for Xen

2016-12-27 Thread Hugo Lefeuvre
Hi, Last month I've gone through most of the CVEs affecting qemu in the past years and investigated whether they were likely to affect the wheezy version of Xen. For that I have considered that any vulnerability affecting the embedded version of Qemu was also affecting Xen, which is, according to