Update Xen bug count in sudoers comment

Closes QubesOS/qubes-issues#2480
This commit is contained in:
Andrew David Wong 2016-12-04 16:30:33 -08:00
parent 044e3d6856
commit 658e02cc50
No known key found for this signature in database
GPG Key ID: 8CE137352A019A17

View File

@ -39,8 +39,8 @@ Background ([/etc/sudoers.d/qubes](https://github.com/QubesOS/qubes-core-agent-l
# and for sure, root/user isolation is not a mitigating factor.
#
# Because, really, if somebody could find and exploit a bug in the Xen
# hypervisor -- so far there have been only one (!) publicly disclosed
# exploitable bug in the Xen hypervisor from a VM, found in 2008,
# hypervisor -- as of 2016, there have been only three publicly disclosed
# exploitable bugs in the Xen hypervisor from a VM -- then it would be
# incidentally by one of the Qubes developers (RW) -- then it would be
# highly unlikely if that person couldn't also found a user-to-root
# escalation in VM (which as we know from history of UNIX/Linux