Debian DSA-3847-1 : xen - security update
High Nessus Plugin ID 100071
SynopsisThe remote Debian host is missing a security-related update.
DescriptionJan Beulich and Jann Horn discovered multiple vulnerabilities in the Xen hypervisor, which may lead to privilege escalation, guest-to-host breakout, denial of service or information leaks.
In additional to the CVE identifiers listed above, this update also addresses the vulnerabilities announced as XSA-213, XSA-214 and XSA-215.
SolutionUpgrade the xen packages.
For the stable distribution (jessie), these problems have been fixed in version 4.4.1-9+deb8u9.
For the upcoming stable distribution (stretch), these problems have been fixed in version 4.8.1-1+deb9u1.