3 ms·
The real oops is that the boundary they are using as a trust boundary is not considered a trust boundary by its developers. Plainly, > the netback driver runs
by blattimwind 7y ago
The real oops is that the boundary they are using as a trust boundary is not considered a trust boundary by its developers. Plainly,
> the netback driver runs in dom0 and is fully trusted. It is coded to protect itself against misbehaving client VMs. Netfront, by contrast, assumes that netback is trustworthy. The Xen developers only considers bugs in netback to be security critical.
> What can an attacker do once they’ve exploited FirewallVM’s trusting netfront driver? Presumably they now have complete control of FirewallVM. At this point, they can simply reuse the same exploit to take control of the client VMs, which are running the same trusting netfront code!