Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-10093

Опубликовано: 17 дек. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-10093: virt:kvm_utils security update (IMPORTANT)

hivex libguestfs [1.40.2-28.0.4]

  • v2v: Cope with libvirt vpx/esx driver which does not set [Orabug: 34026544]

[1.40.2-28.0.3]

  • virt-v2v: Specify backing file format to qemu-img command [Orabug: 33906330]
  • Require 'kernel-uek' RPM for installation instead of 'kernel' [Orabug: 33986812]

[1.40.2-28.0.2]

  • Specify backing file format to qemu-img command [Orabug: 33841090]
  • Add btrfs-progs package to appliance image [Orabug: 33835508]

[1.40.2-28.0.1]

  • Replace upstream references from description tag
  • Config supermin to use host yum.conf in ol8 [Orabug: 29319324]
  • Set DISTRO_ORACLE_LINUX correspeonding to ol

[1:1.40.2-28]

  • daemon: lvm: Use lvcreate --yes to avoid interactive prompts resolves: rhbz#1933640

[1:1.40.2-27]

  • selinux-relabel does not work if SELINUXTYPE != targeted
  • tar-in command does not allow restoring file capabilities resolves: rhbz#1384241 rhbz#1828952

[1:1.40.2-26]

  • insufficient default memsize to open anaconda default RHEL 8.2 luks device resolves: rhbz#1837765

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module virt:kvm_utils is enabled

hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

hivex-devel

1.3.18-21.module+el8.7.0+20889+ec3df884

libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-bash-completion

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-benchmarking

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gfs2

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gobject

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gobject-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-inspect-icons

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-java

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-java-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-javadoc

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-man-pages-ja

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-man-pages-uk

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-rescue

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-rsync

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-tools

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-tools-c

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-winsupport

8.2-1.module+el8.7.0+20889+ec3df884

libguestfs-xfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libiscsi

1.18.0-8.module+el8.7.0+20889+ec3df884

libiscsi-devel

1.18.0-8.module+el8.7.0+20889+ec3df884

libiscsi-utils

1.18.0-8.module+el8.7.0+20889+ec3df884

libnbd

1.2.2-1.module+el8.7.0+20889+ec3df884

libnbd-devel

1.2.2-1.module+el8.7.0+20889+ec3df884

libvirt

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-admin

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-bash-completion

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-client

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-config-network

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-config-nwfilter

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-interface

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-network

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-nodedev

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-nwfilter

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-qemu

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-secret

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-core

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-disk

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-gluster

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-iscsi

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-iscsi-direct

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-logical

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-mpath

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-rbd

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-scsi

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-kvm

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-dbus

1.3.0-2.module+el8.7.0+20889+ec3df884

libvirt-devel

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-docs

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-libs

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-lock-sanlock

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-nss

5.7.0-38.module+el8.7.0+20889+ec3df884

lua-guestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

nbdfuse

1.2.2-1.module+el8.7.0+20889+ec3df884

nbdkit

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-bash-completion

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-basic-filters

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-basic-plugins

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-curl-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-devel

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-example-plugins

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-gzip-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-linuxdisk-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-python-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-server

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-ssh-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-xz-filter

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

netcf

0.2.8-12.module+el8.7.0+20889+ec3df884

netcf-devel

0.2.8-12.module+el8.7.0+20889+ec3df884

netcf-libs

0.2.8-12.module+el8.7.0+20889+ec3df884

perl-Sys-Guestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

perl-Sys-Virt

4.5.0-5.module+el8.7.0+20889+ec3df884

perl-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

python3-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

python3-libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

python3-libnbd

1.2.2-1.module+el8.7.0+20889+ec3df884

python3-libvirt

5.7.0-38.module+el8.7.0+20889+ec3df884

qemu-guest-agent

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-img

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-curl

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-gluster

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-iscsi

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-rbd

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-ssh

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-common

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-core

4.2.1-22.module+el8.7.0+20889+ec3df884

ruby-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

ruby-libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

supermin

5.1.19-10.module+el8.7.0+20889+ec3df884

supermin-devel

5.1.19-10.module+el8.7.0+20889+ec3df884

virt-dib

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

Oracle Linux x86_64

Module virt:kvm_utils is enabled

hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

hivex-devel

1.3.18-21.module+el8.7.0+20889+ec3df884

libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-bash-completion

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-benchmarking

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gfs2

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gobject

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-gobject-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-inspect-icons

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-java

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-java-devel

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-javadoc

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-man-pages-ja

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-man-pages-uk

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-rescue

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-rsync

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-tools

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-tools-c

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libguestfs-winsupport

8.2-1.module+el8.7.0+20889+ec3df884

libguestfs-xfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

libiscsi

1.18.0-8.module+el8.7.0+20889+ec3df884

libiscsi-devel

1.18.0-8.module+el8.7.0+20889+ec3df884

libiscsi-utils

1.18.0-8.module+el8.7.0+20889+ec3df884

libnbd

1.2.2-1.module+el8.7.0+20889+ec3df884

libnbd-devel

1.2.2-1.module+el8.7.0+20889+ec3df884

libvirt

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-admin

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-bash-completion

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-client

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-config-network

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-config-nwfilter

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-interface

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-network

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-nodedev

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-nwfilter

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-qemu

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-secret

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-core

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-disk

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-gluster

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-iscsi

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-iscsi-direct

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-logical

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-mpath

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-rbd

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-driver-storage-scsi

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-daemon-kvm

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-dbus

1.3.0-2.module+el8.7.0+20889+ec3df884

libvirt-devel

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-docs

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-libs

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-lock-sanlock

5.7.0-38.module+el8.7.0+20889+ec3df884

libvirt-nss

5.7.0-38.module+el8.7.0+20889+ec3df884

lua-guestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

nbdfuse

1.2.2-1.module+el8.7.0+20889+ec3df884

nbdkit

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-bash-completion

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-basic-filters

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-basic-plugins

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-curl-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-devel

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-example-plugins

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-gzip-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-linuxdisk-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-python-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-server

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-ssh-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-vddk-plugin

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

nbdkit-xz-filter

1.16.2-4.0.1.module+el8.7.0+20889+ec3df884

netcf

0.2.8-12.module+el8.7.0+20889+ec3df884

netcf-devel

0.2.8-12.module+el8.7.0+20889+ec3df884

netcf-libs

0.2.8-12.module+el8.7.0+20889+ec3df884

perl-Sys-Guestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

perl-Sys-Virt

4.5.0-5.module+el8.7.0+20889+ec3df884

perl-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

python3-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

python3-libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

python3-libnbd

1.2.2-1.module+el8.7.0+20889+ec3df884

python3-libvirt

5.7.0-38.module+el8.7.0+20889+ec3df884

qemu-guest-agent

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-img

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-curl

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-gluster

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-iscsi

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-rbd

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-block-ssh

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-common

4.2.1-22.module+el8.7.0+20889+ec3df884

qemu-kvm-core

4.2.1-22.module+el8.7.0+20889+ec3df884

ruby-hivex

1.3.18-21.module+el8.7.0+20889+ec3df884

ruby-libguestfs

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

seabios

1.13.0-2.module+el8.7.0+20889+ec3df884

seabios-bin

1.13.0-2.module+el8.7.0+20889+ec3df884

seavgabios-bin

1.13.0-2.module+el8.7.0+20889+ec3df884

sgabios

0.20170427git-3.module+el8.7.0+20889+ec3df884

sgabios-bin

0.20170427git-3.module+el8.7.0+20889+ec3df884

supermin

5.1.19-10.module+el8.7.0+20889+ec3df884

supermin-devel

5.1.19-10.module+el8.7.0+20889+ec3df884

virt-dib

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

virt-v2v

1.40.2-28.0.4.module+el8.7.0+20889+ec3df884

Связанные CVE

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 3
redhat
около 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
nvd
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.3
debian
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pa ...