UpCloud and VENOM, CVE-2015-3456, Security Vulnerability

  • Author

    Joel Pihlajamaa

    CTO & Founder

  • About

    Type
    Blog
    Category
    Announcements

Posted on 14 May 2015

Yesterday, on Wednesday 13th, 2015, Crowdstrike announced information regarding a security vulnerability they had discovered in the floppy disk controller on QEMU. The vulnerability allows an attacker to escape the confinement of the Virtual Machine guest operating system and gain privileged access to the host machine.

Since a key component of security in virtualised environments is the ability to limit access to guest operating systems only, patching this vulnerability was of major importance immediately when we saw it.

Last night, at around 17.30 UTC, we informed all our customers via e-mail about the patching process that would begin later that night at 19.00 UTC. We did not want to publicly announce anything since this would have given notice to potential exploiters as well. This morning, at 6:28 UTC, all UpCloud’s host machines in all three service areas had been patched.

While this project was enormous given such a short time frame, with the forced security updates we were able to migrate all customers to updated host machines. We were able to decommission, in an accelerated fashion, a large number of older host machines resulting in better performance and reliability for our customers at large.

The CVE-2015-3456 advisory is not an issue on UpCloud anymore and we want to thank our customers for co-operating with us on such a short notice. We continue to monitor all announcements and advisories regarding the different components we use in our infrastructure to keep our service as secure as possible.

Discussion

Leave a Reply

Your email address will not be published. Required fields are marked *

Cloud promotion!

Start your free 30-day trial today and discover why thousands of businesses trust UpCloud

  • $500 free credits
  • Risk-free trial
  • Optimized performance
  • Scalable infrastructure
  • Top-tier security
  • Global availability

Sign up

See also

Databases in the cloud: Developing on the database-as-a-service model.

Databases in the cloud: Developing on the database-as-a-service model

In this fourth edition in our series of hosting databases in the cloud, we'll be diving into the details of a database-as-a-service model.

Janne Ruostemaa

Editor-in-Chief

Blog post banner about key learnings and insights from Cloudfest 2024.

Key learnings and insights from CloudFest 2024! 

Celebrating its 20th year, CloudFest 2024 sure did bring the party! Uniting almost twelve thousand cloud experts, the event was a true celebration of the […]

Fiona Horan

Enterprise Marketing Specialist

Cover image for a blog post about the evolution of cloud servers in computing.

The evolution of cloud servers in modern computing

Cloud computing has drastically changed how information technology (IT) professionals utilise technology. This infrastructure has enabled businesses to use online tools, platforms, and storage spaces, […]

Janne Ruostemaa

Editor-in-Chief

Back to top