Описание
ELSA-2026-18326: libvirt security update (MODERATE)
[11.10.0-12.4.0.1]
- Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]
[11.10.0-12.4.el10_2]
- cpu_conf: Introduce virCPUDefSortFeatures (RHEL-180449)
- qemu_capabilities: Split virQEMUCapsFillDomainCPUCaps (RHEL-180449)
- qemu: Move domain caps flags handling to virQEMUCapsFillDomainCPUHostModel (RHEL-180449)
- qemu_capabilities: Always sort features in host-model CPU (RHEL-180449)
- qemu_capabilities: Use g_autoptr in virQEMUCapsInitHostCPUModel (RHEL-180449)
- qemu_capabilities: Split conditions in virQEMUCapsInitHostCPUModel (RHEL-180449)
- qemu_capabilities: Cache expanded CPU (RHEL-180449)
- domaincapstest: Test EXPAND_CPU_FEATURES flag (RHEL-180449)
- util: Publish and mock virHostCPUGetMSRFromKVM (RHEL-180449)
- cpu_x86: Introduce virCPUx86DataAddMSR (RHEL-180449)
- cpu: Introduce virCPUUpdateFeatures (RHEL-180449)
- Fix documentation of VIR_CONNECT_GET_DOMAIN_CAPABILITIES_EXPAND_CPU_FEATURES (RHEL-180449)
- Introduce VIR_CONNECT_GET_DOMAIN_CAPABILITIES_SUPPORTED_CPU_FEATURES flag (RHEL-180449)
- virsh: Add --supported-cpu-features option for domcapabilities (RHEL-180449)
- domaincapstest: Test SUPPORTED_CPU_FEATURES flag (RHEL-180449)
- qemu_capabilities: Fix domain capabilities on AMD CPUs (RHEL-180449)
- distro: Replace old gating with tmt
[11.10.0-12.3.el10_2]
- esx: Track VMs by instanceUuid instead of UUID (RHEL-177479)
[11.10.0-12.2.el10_2]
- Introduce EXPAND_CPU_FEATURES flag for domain capabilities (RHEL-154553)
- qemu: Implement VIR_CONNECT_GET_DOMAIN_CAPABILITIES_EXPAND_CPU_FEATURES (RHEL-154553)
- virsh: Add --expand-cpu-features option for domcapabilities (RHEL-154553)
- docs: Clarify host-model description in domain capabilities (RHEL-154553)
- security_apparmor: Use g_auto* in AppArmorSetSecurityHostdevLabel (RHEL-159912)
- security: Cleanup hostdev label error logic (RHEL-159912)
- qemu: Fix IOMMUFD and VFIO security labels (RHEL-159912)
- viriommufd: Set IOMMU_OPTION_RLIMIT_MODE only when running privileged (RHEL-159175)
- conf: Move and rename virStorageSourceFDTuple object (RHEL-159175)
- conf: Refactor virHostdevIsPCIDevice (RHEL-159175)
- hypervisor: Fix virHostdevNeedsVFIO detection (RHEL-159175)
- qemu: Expand call to qemuDomainNeedsVFIO (RHEL-159175)
- qemu: Update qemuDomainNeedsVFIO to ignore PCI hostdev with IOMMUFD (RHEL-159175)
- src: Use virHostdevIsPCIDeviceWith* to check for IOMMUFD (RHEL-159175)
- conf: Introduce domain iommufd element (RHEL-159175)
- qemu: Implement iommufd (RHEL-159175)
- conf: Add iommufd fdgroup support (RHEL-159175)
- qemu: Implement iommufd fdgroup (RHEL-159175)
- tests: Add iommufd fdgroup test (RHEL-159175)
- hypervisor: Call virWaitForDevices() after detaching host devices (RHEL-159175)
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
libvirt
11.10.0-12.4.0.1.el10_2
libvirt-client
11.10.0-12.4.0.1.el10_2
libvirt-client-qemu
11.10.0-12.4.0.1.el10_2
libvirt-daemon
11.10.0-12.4.0.1.el10_2
libvirt-daemon-common
11.10.0-12.4.0.1.el10_2
libvirt-daemon-config-network
11.10.0-12.4.0.1.el10_2
libvirt-daemon-config-nwfilter
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-interface
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-network
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-nodedev
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-nwfilter
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-qemu
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-secret
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-core
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-disk
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-iscsi
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-logical
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-mpath
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-rbd
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-scsi
11.10.0-12.4.0.1.el10_2
libvirt-daemon-kvm
11.10.0-12.4.0.1.el10_2
libvirt-daemon-lock
11.10.0-12.4.0.1.el10_2
libvirt-daemon-log
11.10.0-12.4.0.1.el10_2
libvirt-daemon-plugin-lockd
11.10.0-12.4.0.1.el10_2
libvirt-daemon-plugin-sanlock
11.10.0-12.4.0.1.el10_2
libvirt-daemon-proxy
11.10.0-12.4.0.1.el10_2
libvirt-devel
11.10.0-12.4.0.1.el10_2
libvirt-docs
11.10.0-12.4.0.1.el10_2
libvirt-libs
11.10.0-12.4.0.1.el10_2
libvirt-nss
11.10.0-12.4.0.1.el10_2
libvirt-ssh-proxy
11.10.0-12.4.0.1.el10_2
Oracle Linux x86_64
libvirt
11.10.0-12.4.0.1.el10_2
libvirt-client
11.10.0-12.4.0.1.el10_2
libvirt-client-qemu
11.10.0-12.4.0.1.el10_2
libvirt-daemon
11.10.0-12.4.0.1.el10_2
libvirt-daemon-common
11.10.0-12.4.0.1.el10_2
libvirt-daemon-config-network
11.10.0-12.4.0.1.el10_2
libvirt-daemon-config-nwfilter
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-interface
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-network
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-nodedev
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-nwfilter
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-qemu
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-secret
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-core
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-disk
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-iscsi
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-logical
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-mpath
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-rbd
11.10.0-12.4.0.1.el10_2
libvirt-daemon-driver-storage-scsi
11.10.0-12.4.0.1.el10_2
libvirt-daemon-kvm
11.10.0-12.4.0.1.el10_2
libvirt-daemon-lock
11.10.0-12.4.0.1.el10_2
libvirt-daemon-log
11.10.0-12.4.0.1.el10_2
libvirt-daemon-plugin-lockd
11.10.0-12.4.0.1.el10_2
libvirt-daemon-plugin-sanlock
11.10.0-12.4.0.1.el10_2
libvirt-daemon-proxy
11.10.0-12.4.0.1.el10_2
libvirt-devel
11.10.0-12.4.0.1.el10_2
libvirt-docs
11.10.0-12.4.0.1.el10_2
libvirt-libs
11.10.0-12.4.0.1.el10_2
libvirt-nss
11.10.0-12.4.0.1.el10_2
libvirt-ssh-proxy
11.10.0-12.4.0.1.el10_2
Связанные CVE
Связанные уязвимости
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More spec ...