Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5674

Опубликовано: 07 мая 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-5674: libvirt security update (IMPORTANT)

[5.7.0-13.el7]

  • domain groups: Fix multiple Domain Group vCPU administration flaws (Wim ten Have) [Orabug: 31145304]
  • qemu: fix missing #if defined(ENABLE_EXADATA) (Menno Lageman)
  • build: Fix qemu-submodule-init syntax-check issue (Wim ten Have)
  • libvirt: Fix various introduced Fedora/RHEL build violations (Wim ten Have) [Orabug: 31143337]
  • qemu: don't hold both jobs for suspend (Jonathon Jongsma) [Orabug: 31073098] {CVE-2019-20485}
  • domain groups: qemu driver error refers to pCPUs instead of vCPUs (Wim ten Have) [Orabug: 31075757]
  • node_device_conf: Don't leak @physical_function in virNodeDeviceGetPCISRIOVCaps (Jiang Kun) [Orabug: 31070337]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libvirt

5.7.0-13.el7

libvirt-admin

5.7.0-13.el7

libvirt-bash-completion

5.7.0-13.el7

libvirt-client

5.7.0-13.el7

libvirt-daemon

5.7.0-13.el7

libvirt-daemon-config-network

5.7.0-13.el7

libvirt-daemon-config-nwfilter

5.7.0-13.el7

libvirt-daemon-driver-interface

5.7.0-13.el7

libvirt-daemon-driver-lxc

5.7.0-13.el7

libvirt-daemon-driver-network

5.7.0-13.el7

libvirt-daemon-driver-nodedev

5.7.0-13.el7

libvirt-daemon-driver-nwfilter

5.7.0-13.el7

libvirt-daemon-driver-qemu

5.7.0-13.el7

libvirt-daemon-driver-secret

5.7.0-13.el7

libvirt-daemon-driver-storage

5.7.0-13.el7

libvirt-daemon-driver-storage-core

5.7.0-13.el7

libvirt-daemon-driver-storage-disk

5.7.0-13.el7

libvirt-daemon-driver-storage-gluster

5.7.0-13.el7

libvirt-daemon-driver-storage-iscsi

5.7.0-13.el7

libvirt-daemon-driver-storage-logical

5.7.0-13.el7

libvirt-daemon-driver-storage-mpath

5.7.0-13.el7

libvirt-daemon-driver-storage-rbd

5.7.0-13.el7

libvirt-daemon-driver-storage-scsi

5.7.0-13.el7

libvirt-daemon-kvm

5.7.0-13.el7

libvirt-daemon-lxc

5.7.0-13.el7

libvirt-daemon-qemu

5.7.0-13.el7

libvirt-devel

5.7.0-13.el7

libvirt-docs

5.7.0-13.el7

libvirt-libs

5.7.0-13.el7

libvirt-lock-sanlock

5.7.0-13.el7

libvirt-login-shell

5.7.0-13.el7

libvirt-nss

5.7.0-13.el7

Oracle Linux x86_64

libvirt

5.7.0-13.el7

libvirt-admin

5.7.0-13.el7

libvirt-bash-completion

5.7.0-13.el7

libvirt-client

5.7.0-13.el7

libvirt-daemon

5.7.0-13.el7

libvirt-daemon-config-network

5.7.0-13.el7

libvirt-daemon-config-nwfilter

5.7.0-13.el7

libvirt-daemon-driver-interface

5.7.0-13.el7

libvirt-daemon-driver-lxc

5.7.0-13.el7

libvirt-daemon-driver-network

5.7.0-13.el7

libvirt-daemon-driver-nodedev

5.7.0-13.el7

libvirt-daemon-driver-nwfilter

5.7.0-13.el7

libvirt-daemon-driver-qemu

5.7.0-13.el7

libvirt-daemon-driver-secret

5.7.0-13.el7

libvirt-daemon-driver-storage

5.7.0-13.el7

libvirt-daemon-driver-storage-core

5.7.0-13.el7

libvirt-daemon-driver-storage-disk

5.7.0-13.el7

libvirt-daemon-driver-storage-gluster

5.7.0-13.el7

libvirt-daemon-driver-storage-iscsi

5.7.0-13.el7

libvirt-daemon-driver-storage-logical

5.7.0-13.el7

libvirt-daemon-driver-storage-mpath

5.7.0-13.el7

libvirt-daemon-driver-storage-rbd

5.7.0-13.el7

libvirt-daemon-driver-storage-scsi

5.7.0-13.el7

libvirt-daemon-kvm

5.7.0-13.el7

libvirt-daemon-lxc

5.7.0-13.el7

libvirt-daemon-qemu

5.7.0-13.el7

libvirt-devel

5.7.0-13.el7

libvirt-docs

5.7.0-13.el7

libvirt-libs

5.7.0-13.el7

libvirt-lock-sanlock

5.7.0-13.el7

libvirt-login-shell

5.7.0-13.el7

libvirt-nss

5.7.0-13.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.8
redhat
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
nvd
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
debian
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a ...

CVSS3: 5.7
github
около 3 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).