Описание
ELSA-2026-18748: libvirt security update (MODERATE)
[11.10.0-12.3.0.1]
- Set SOURCE_DATE_EPOCH from changelog [Orabug: 32019554]
[11.10.0-12.3.el9_8]
- cpu_conf: Introduce virCPUDefSortFeatures (RHEL-178822)
- qemu_capabilities: Split virQEMUCapsFillDomainCPUCaps (RHEL-178822)
- qemu: Move domain caps flags handling to virQEMUCapsFillDomainCPUHostModel (RHEL-178822)
- qemu_capabilities: Always sort features in host-model CPU (RHEL-178822)
- qemu_capabilities: Use g_autoptr in virQEMUCapsInitHostCPUModel (RHEL-178822)
- qemu_capabilities: Split conditions in virQEMUCapsInitHostCPUModel (RHEL-178822)
- qemu_capabilities: Cache expanded CPU (RHEL-178822)
- domaincapstest: Test EXPAND_CPU_FEATURES flag (RHEL-178822)
- util: Publish and mock virHostCPUGetMSRFromKVM (RHEL-178822)
- cpu_x86: Introduce virCPUx86DataAddMSR (RHEL-178822)
- cpu: Introduce virCPUUpdateFeatures (RHEL-178822)
- Fix documentation of VIR_CONNECT_GET_DOMAIN_CAPABILITIES_EXPAND_CPU_FEATURES (RHEL-178822)
- Introduce VIR_CONNECT_GET_DOMAIN_CAPABILITIES_SUPPORTED_CPU_FEATURES flag (RHEL-178822)
- virsh: Add --supported-cpu-features option for domcapabilities (RHEL-178822)
- domaincapstest: Test SUPPORTED_CPU_FEATURES flag (RHEL-178822)
- qemu_capabilities: Fix domain capabilities on AMD CPUs (RHEL-178822)
- distro: Replace old gating with tmt
[11.10.0-12.2.el9_8]
- Introduce EXPAND_CPU_FEATURES flag for domain capabilities (RHEL-154552)
- qemu: Implement VIR_CONNECT_GET_DOMAIN_CAPABILITIES_EXPAND_CPU_FEATURES (RHEL-154552)
- virsh: Add --expand-cpu-features option for domcapabilities (RHEL-154552)
- docs: Clarify host-model description in domain capabilities (RHEL-154552)
- security_apparmor: Use g_auto* in AppArmorSetSecurityHostdevLabel (RHEL-159913)
- security: Cleanup hostdev label error logic (RHEL-159913)
- qemu: Fix IOMMUFD and VFIO security labels (RHEL-159913)
- viriommufd: Set IOMMU_OPTION_RLIMIT_MODE only when running privileged (RHEL-159174)
- conf: Move and rename virStorageSourceFDTuple object (RHEL-159174)
- conf: Refactor virHostdevIsPCIDevice (RHEL-159174)
- hypervisor: Fix virHostdevNeedsVFIO detection (RHEL-159174)
- qemu: Expand call to qemuDomainNeedsVFIO (RHEL-159174)
- qemu: Update qemuDomainNeedsVFIO to ignore PCI hostdev with IOMMUFD (RHEL-159174)
- src: Use virHostdevIsPCIDeviceWith* to check for IOMMUFD (RHEL-159174)
- conf: Introduce domain iommufd element (RHEL-159174)
- qemu: Implement iommufd (RHEL-159174)
- conf: Add iommufd fdgroup support (RHEL-159174)
- qemu: Implement iommufd fdgroup (RHEL-159174)
- tests: Add iommufd fdgroup test (RHEL-159174)
- hypervisor: Call virWaitForDevices() after detaching host devices (RHEL-159174)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
libvirt-daemon-plugin-sanlock
11.10.0-12.3.0.1.el9_8
libvirt-devel
11.10.0-12.3.0.1.el9_8
libvirt-docs
11.10.0-12.3.0.1.el9_8
libvirt
11.10.0-12.3.0.1.el9_8
libvirt-client
11.10.0-12.3.0.1.el9_8
libvirt-client-qemu
11.10.0-12.3.0.1.el9_8
libvirt-daemon
11.10.0-12.3.0.1.el9_8
libvirt-daemon-common
11.10.0-12.3.0.1.el9_8
libvirt-daemon-config-network
11.10.0-12.3.0.1.el9_8
libvirt-daemon-config-nwfilter
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-interface
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-network
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-nodedev
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-nwfilter
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-qemu
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-secret
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-core
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-disk
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-iscsi
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-logical
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-mpath
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-rbd
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-scsi
11.10.0-12.3.0.1.el9_8
libvirt-daemon-kvm
11.10.0-12.3.0.1.el9_8
libvirt-daemon-lock
11.10.0-12.3.0.1.el9_8
libvirt-daemon-log
11.10.0-12.3.0.1.el9_8
libvirt-daemon-plugin-lockd
11.10.0-12.3.0.1.el9_8
libvirt-daemon-proxy
11.10.0-12.3.0.1.el9_8
libvirt-libs
11.10.0-12.3.0.1.el9_8
libvirt-nss
11.10.0-12.3.0.1.el9_8
libvirt-ssh-proxy
11.10.0-12.3.0.1.el9_8
Oracle Linux x86_64
libvirt
11.10.0-12.3.0.1.el9_8
libvirt-client
11.10.0-12.3.0.1.el9_8
libvirt-client-qemu
11.10.0-12.3.0.1.el9_8
libvirt-daemon
11.10.0-12.3.0.1.el9_8
libvirt-daemon-common
11.10.0-12.3.0.1.el9_8
libvirt-daemon-config-network
11.10.0-12.3.0.1.el9_8
libvirt-daemon-config-nwfilter
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-interface
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-network
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-nodedev
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-nwfilter
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-qemu
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-secret
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-core
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-disk
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-iscsi
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-logical
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-mpath
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-rbd
11.10.0-12.3.0.1.el9_8
libvirt-daemon-driver-storage-scsi
11.10.0-12.3.0.1.el9_8
libvirt-daemon-kvm
11.10.0-12.3.0.1.el9_8
libvirt-daemon-lock
11.10.0-12.3.0.1.el9_8
libvirt-daemon-log
11.10.0-12.3.0.1.el9_8
libvirt-daemon-plugin-lockd
11.10.0-12.3.0.1.el9_8
libvirt-daemon-proxy
11.10.0-12.3.0.1.el9_8
libvirt-libs
11.10.0-12.3.0.1.el9_8
libvirt-nss
11.10.0-12.3.0.1.el9_8
libvirt-ssh-proxy
11.10.0-12.3.0.1.el9_8
libvirt-daemon-plugin-sanlock
11.10.0-12.3.0.1.el9_8
libvirt-devel
11.10.0-12.3.0.1.el9_8
libvirt-docs
11.10.0-12.3.0.1.el9_8
Связанные CVE
Связанные уязвимости
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the host, resulting in a denial-of-service condition.
A flaw was discovered in libvirt in the XML file processing. More spec ...