Описание
ELSA-2022-8003: libvirt security, bug fix, and enhancement update (LOW)
[8.5.0-7.0.1]
- Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]
[8.5.0-7]
- security_selinux: Dont ignore NVMe disks when setting image label (rhbz#2121441)
[8.5.0-6]
- qemu_process: Destroy domains namespace after killing QEMU (rhbz#2121141)
[8.5.0-5]
- rpc: Pass OPENSSL_CONF through to ssh invocations (rhbz#2112348)
[8.5.0-4]
- qemu: Pass migration flags to qemuMigrationParamsApply (rhbz#2111070)
- qemu_migration_params: Replace qemuMigrationParamTypes array (rhbz#2111070)
- qemu_migration: Pass migParams to qemuMigrationSrcResume (rhbz#2111070)
- qemu_migration: Apply max-postcopy-bandwidth on post-copy resume (rhbz#2111070)
- qemu: Always assume support for QEMU_CAPS_MIGRATION_PARAM_XBZRLE_CACHE_SIZE (rhbz#2107892)
- qemu_migration: Store original migration params in status XML (rhbz#2107892)
- qemu_migration_params: Refactor qemuMigrationParamsApply (rhbz#2107892)
- qemu_migration_params: Refactor qemuMigrationParamsReset (rhbz#2107892)
- qemu_migration_params: Avoid deadlock in qemuMigrationParamsReset (rhbz#2107892)
- qemu: Restore original memory locking limit on reconnect (rhbz#2107424)
- qemu: Properly release job in qemuDomainSaveInternal (rhbz#1497907)
- qemu: dont call qemuMigrationSrcIsAllowedHostdev() from qemuMigrationDstPrepareFresh() (rhbz#1497907)
[8.5.0-3]
- qemu: introduce capability QEMU_CAPS_MIGRATION_BLOCKED_REASONS (rhbz#2092833)
- qemu: new function to retrieve migration blocker reasons from QEMU (rhbz#2092833)
- qemu: query QEMU for migration blockers before our own harcoded checks (rhbz#2092833)
- qemu: remove hardcoded migration fail for vDPA devices if we can ask QEMU (rhbz#2092833)
- qemu_migration: Use EnterMonitorAsync in qemuDomainGetMigrationBlockers (rhbz#2092833)
- qemu: dont try to query QEMU about migration blockers during offline migration (rhbz#2092833)
- qemu_migration: Acquire correct job in qemuMigrationSrcIsAllowed (rhbz#2092833)
- virsh: Require --xpath for *dumpxml (rhbz#2103524)
- qemu: skip hardcoded hostdev migration check if QEMU can do it for us (rhbz#1497907)
[8.5.0-2]
- domain_conf: Format more often (rhbz#2059511)
- domain_conf: Format iothread IDs more often (rhbz#2059511)
- qemu: Make IOThread changing more robust (rhbz#2059511)
- qemuDomainSetIOThreadParams: Accept VIR_DOMAIN_AFFECT_CONFIG flag (rhbz#2059511)
- virsh: Implement --config for iothreadset (rhbz#2059511)
- docs: Document TPM portion of domcaps (rhbz#2103119)
- virtpm: Introduce TPM-1.2 and TPM-2.0 capabilieis (rhbz#2103119)
- domcaps: Introduce TPM backendVersion (rhbz#2103119)
- qemu: Report supported TPM version in domcaps (rhbz#2103119)
- vircpi: Add PCIe 5.0 and 6.0 link speeds (rhbz#2105231)
[8.5.0-1]
- Rebased to libvirt-8.5.0 (rhbz#2060313)
- The rebase also fixes the following bugs: rhbz#1475431, rhbz#2026765, rhbz#2059511, rhbz#2089431, rhbz#2102009
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
libvirt
8.5.0-7.0.1.el9_1
libvirt-client
8.5.0-7.0.1.el9_1
libvirt-daemon
8.5.0-7.0.1.el9_1
libvirt-daemon-config-network
8.5.0-7.0.1.el9_1
libvirt-daemon-config-nwfilter
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-interface
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-network
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-nodedev
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-nwfilter
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-qemu
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-secret
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-core
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-disk
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-iscsi
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-logical
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-mpath
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-rbd
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-scsi
8.5.0-7.0.1.el9_1
libvirt-daemon-kvm
8.5.0-7.0.1.el9_1
libvirt-devel
8.5.0-7.0.1.el9_1
libvirt-docs
8.5.0-7.0.1.el9_1
libvirt-libs
8.5.0-7.0.1.el9_1
libvirt-lock-sanlock
8.5.0-7.0.1.el9_1
libvirt-nss
8.5.0-7.0.1.el9_1
Oracle Linux x86_64
libvirt
8.5.0-7.0.1.el9_1
libvirt-client
8.5.0-7.0.1.el9_1
libvirt-daemon
8.5.0-7.0.1.el9_1
libvirt-daemon-config-network
8.5.0-7.0.1.el9_1
libvirt-daemon-config-nwfilter
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-interface
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-network
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-nodedev
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-nwfilter
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-qemu
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-secret
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-core
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-disk
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-iscsi
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-logical
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-mpath
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-rbd
8.5.0-7.0.1.el9_1
libvirt-daemon-driver-storage-scsi
8.5.0-7.0.1.el9_1
libvirt-daemon-kvm
8.5.0-7.0.1.el9_1
libvirt-devel
8.5.0-7.0.1.el9_1
libvirt-docs
8.5.0-7.0.1.el9_1
libvirt-libs
8.5.0-7.0.1.el9_1
libvirt-lock-sanlock
8.5.0-7.0.1.el9_1
libvirt-nss
8.5.0-7.0.1.el9_1
Связанные CVE
Связанные уязвимости
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...