Description of the patch:
XEN has been updated to fix various bugs and security issues:
*
CVE-2013-0153: (XSA 36) To avoid an erratum in early hardware, the
Xen AMD IOMMU code by default choose to use a single interrupt
remapping table for the whole system. This sharing implied that any
guest with a passed through PCI device that is bus mastering capable
can inject interrupts into other guests, including domain 0. This has
been disabled for AMD chipsets not capable of it.
*
CVE-2012-6075: qemu: The e1000 had overflows under some conditions,
potentially corrupting memory.
*
CVE-2013-0154: (XSA 37) Hypervisor crash due to incorrect ASSERT
(debug build only)
*
CVE-2012-5634: (XSA-33) A VT-d interrupt remapping source validation
flaw was fixed.
Also the following bugs have been fixed:
* bnc#805094 - xen hot plug attach/detach fails
* bnc#802690 - domain locking can prevent a live migration from
completing
* bnc#797014 - no way to control live migrations
o fix logic error in stdiostream_progress
o restore logging in xc_save
o add options to control migration tunables
* bnc#806736: enabling xentrace crashes hypervisor
* Upstream patches from Jan 26287-sched-credit-pick-idle.patch
26501-VMX-simplify-CR0-update.patch
26502-VMX-disable-SMEP-when-not-paging.patch
26516-ACPI-parse-table-retval.patch (Replaces
CVE-2013-0153-xsa36.patch) 26517-AMD-IOMMU-clear-irtes.patch
(Replaces CVE-2013-0153-xsa36.patch)
26518-AMD-IOMMU-disable-if-SATA-combined-mode.patch (Replaces
CVE-2013-0153-xsa36.patch)
26519-AMD-IOMMU-perdev-intremap-default.patch (Replaces
CVE-2013-0153-xsa36.patch) 26526-pvdrv-no-devinit.patch
26531-AMD-IOMMU-IVHD-special-missing.patch (Replaces
CVE-2013-0153-xsa36.patch)
* bnc#798188 - Add $network to xend initscript dependencies
*...
4.1.4_02-0.5.14.1.6_08-0.11.14.1.4_02-0.5.14.1.4_02-0.5.14.1.4_02_3.0.58_0.6.6-0.5.14.1.4_02_3.0.58_0.6.6-0.5.14.1.4_02_3.0.58_0.6.6-0.5.14.1.4_02-0.5.14.1.4_02-0.5.14.1.4_02-0.5.1