3 ms·
Memories are short. What about VENOM https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456 w
by sn 11y ago
Memories are short. What about VENOM https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456 which affected both Xen HVM and KVM? Then there was http://xenbits.xen.org/xsa/advisory-110.html http://xenbits.xen.org/xsa/advisory-110.html which is privilege escalation in HVM mode.
Regardless of the virtualization technology, you need to keep on top of disclosures. Any public provider running xen should be on the disclosure list by now http://www.xenproject.org/security-policy.html http://www.xenproject.org/security-policy.html