Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-8003

Опубликовано: 22 нояб. 2022
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2022-8003: libvirt security, bug fix, and enhancement update (LOW)

[8.5.0-7.0.1]

  • Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]

[8.5.0-7]

  • security_selinux: Dont ignore NVMe disks when setting image label (rhbz#2121441)

[8.5.0-6]

  • qemu_process: Destroy domains namespace after killing QEMU (rhbz#2121141)

[8.5.0-5]

  • rpc: Pass OPENSSL_CONF through to ssh invocations (rhbz#2112348)

[8.5.0-4]

  • qemu: Pass migration flags to qemuMigrationParamsApply (rhbz#2111070)
  • qemu_migration_params: Replace qemuMigrationParamTypes array (rhbz#2111070)
  • qemu_migration: Pass migParams to qemuMigrationSrcResume (rhbz#2111070)
  • qemu_migration: Apply max-postcopy-bandwidth on post-copy resume (rhbz#2111070)
  • qemu: Always assume support for QEMU_CAPS_MIGRATION_PARAM_XBZRLE_CACHE_SIZE (rhbz#2107892)
  • qemu_migration: Store original migration params in status XML (rhbz#2107892)
  • qemu_migration_params: Refactor qemuMigrationParamsApply (rhbz#2107892)
  • qemu_migration_params: Refactor qemuMigrationParamsReset (rhbz#2107892)
  • qemu_migration_params: Avoid deadlock in qemuMigrationParamsReset (rhbz#2107892)
  • qemu: Restore original memory locking limit on reconnect (rhbz#2107424)
  • qemu: Properly release job in qemuDomainSaveInternal (rhbz#1497907)
  • qemu: dont call qemuMigrationSrcIsAllowedHostdev() from qemuMigrationDstPrepareFresh() (rhbz#1497907)

[8.5.0-3]

  • qemu: introduce capability QEMU_CAPS_MIGRATION_BLOCKED_REASONS (rhbz#2092833)
  • qemu: new function to retrieve migration blocker reasons from QEMU (rhbz#2092833)
  • qemu: query QEMU for migration blockers before our own harcoded checks (rhbz#2092833)
  • qemu: remove hardcoded migration fail for vDPA devices if we can ask QEMU (rhbz#2092833)
  • qemu_migration: Use EnterMonitorAsync in qemuDomainGetMigrationBlockers (rhbz#2092833)
  • qemu: dont try to query QEMU about migration blockers during offline migration (rhbz#2092833)
  • qemu_migration: Acquire correct job in qemuMigrationSrcIsAllowed (rhbz#2092833)
  • virsh: Require --xpath for *dumpxml (rhbz#2103524)
  • qemu: skip hardcoded hostdev migration check if QEMU can do it for us (rhbz#1497907)

[8.5.0-2]

  • domain_conf: Format more often (rhbz#2059511)
  • domain_conf: Format iothread IDs more often (rhbz#2059511)
  • qemu: Make IOThread changing more robust (rhbz#2059511)
  • qemuDomainSetIOThreadParams: Accept VIR_DOMAIN_AFFECT_CONFIG flag (rhbz#2059511)
  • virsh: Implement --config for iothreadset (rhbz#2059511)
  • docs: Document TPM portion of domcaps (rhbz#2103119)
  • virtpm: Introduce TPM-1.2 and TPM-2.0 capabilieis (rhbz#2103119)
  • domcaps: Introduce TPM backendVersion (rhbz#2103119)
  • qemu: Report supported TPM version in domcaps (rhbz#2103119)
  • vircpi: Add PCIe 5.0 and 6.0 link speeds (rhbz#2105231)

[8.5.0-1]

  • Rebased to libvirt-8.5.0 (rhbz#2060313)
  • The rebase also fixes the following bugs: rhbz#1475431, rhbz#2026765, rhbz#2059511, rhbz#2089431, rhbz#2102009

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libvirt

8.5.0-7.0.1.el9_1

libvirt-client

8.5.0-7.0.1.el9_1

libvirt-daemon

8.5.0-7.0.1.el9_1

libvirt-daemon-config-network

8.5.0-7.0.1.el9_1

libvirt-daemon-config-nwfilter

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-interface

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-network

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-nodedev

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-nwfilter

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-qemu

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-secret

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-core

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-disk

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-iscsi

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-logical

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-mpath

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-rbd

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-scsi

8.5.0-7.0.1.el9_1

libvirt-daemon-kvm

8.5.0-7.0.1.el9_1

libvirt-devel

8.5.0-7.0.1.el9_1

libvirt-docs

8.5.0-7.0.1.el9_1

libvirt-libs

8.5.0-7.0.1.el9_1

libvirt-lock-sanlock

8.5.0-7.0.1.el9_1

libvirt-nss

8.5.0-7.0.1.el9_1

Oracle Linux x86_64

libvirt

8.5.0-7.0.1.el9_1

libvirt-client

8.5.0-7.0.1.el9_1

libvirt-daemon

8.5.0-7.0.1.el9_1

libvirt-daemon-config-network

8.5.0-7.0.1.el9_1

libvirt-daemon-config-nwfilter

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-interface

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-network

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-nodedev

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-nwfilter

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-qemu

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-secret

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-core

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-disk

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-iscsi

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-logical

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-mpath

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-rbd

8.5.0-7.0.1.el9_1

libvirt-daemon-driver-storage-scsi

8.5.0-7.0.1.el9_1

libvirt-daemon-kvm

8.5.0-7.0.1.el9_1

libvirt-devel

8.5.0-7.0.1.el9_1

libvirt-docs

8.5.0-7.0.1.el9_1

libvirt-libs

8.5.0-7.0.1.el9_1

libvirt-lock-sanlock

8.5.0-7.0.1.el9_1

libvirt-nss

8.5.0-7.0.1.el9_1

Связанные CVE

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 5
redhat
больше 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
nvd
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
debian
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

suse-cvrf
почти 2 года назад

Security update for libvirt

Уязвимость ELSA-2022-8003