Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:2652-1

Опубликовано: 27 июн. 2023
Источник: suse-cvrf

Описание

Security update for libvirt

This update for libvirt fixes the following issues:

  • CVE-2023-2700: virpci: Resolve leak in virPCIVirtualFunctionList (bsc#1211390)
  • apparmor: Add support for local profile customizations (bsc#1211472)
  • qemu: Fix cdrom media change (bsc#1210666)
  • qemu: Fix potential crash during driver cleanup (bsc#1209861)

Список пакетов

Image SLES15-SP5-SAP-Azure-3P
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-BYOS-Azure
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-BYOS-EC2
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-BYOS-GCE
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Hardened-Azure
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Hardened-GCE
libvirt-client-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
libvirt-libs-9.0.0-150500.6.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
libvirt-9.0.0-150500.6.3.1
libvirt-client-9.0.0-150500.6.3.1
libvirt-client-qemu-9.0.0-150500.6.3.1
libvirt-daemon-9.0.0-150500.6.3.1
libvirt-daemon-config-network-9.0.0-150500.6.3.1
libvirt-daemon-config-nwfilter-9.0.0-150500.6.3.1
libvirt-daemon-driver-interface-9.0.0-150500.6.3.1
libvirt-daemon-driver-libxl-9.0.0-150500.6.3.1
libvirt-daemon-driver-network-9.0.0-150500.6.3.1
libvirt-daemon-driver-nodedev-9.0.0-150500.6.3.1
libvirt-daemon-driver-nwfilter-9.0.0-150500.6.3.1
libvirt-daemon-driver-qemu-9.0.0-150500.6.3.1
libvirt-daemon-driver-secret-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-core-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-disk-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-logical-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.3.1
libvirt-daemon-hooks-9.0.0-150500.6.3.1
libvirt-daemon-qemu-9.0.0-150500.6.3.1
libvirt-daemon-xen-9.0.0-150500.6.3.1
libvirt-devel-9.0.0-150500.6.3.1
libvirt-doc-9.0.0-150500.6.3.1
libvirt-lock-sanlock-9.0.0-150500.6.3.1
libvirt-nss-9.0.0-150500.6.3.1
openSUSE Leap 15.5
libvirt-9.0.0-150500.6.3.1
libvirt-client-9.0.0-150500.6.3.1
libvirt-client-qemu-9.0.0-150500.6.3.1
libvirt-daemon-9.0.0-150500.6.3.1
libvirt-daemon-config-network-9.0.0-150500.6.3.1
libvirt-daemon-config-nwfilter-9.0.0-150500.6.3.1
libvirt-daemon-driver-interface-9.0.0-150500.6.3.1
libvirt-daemon-driver-libxl-9.0.0-150500.6.3.1
libvirt-daemon-driver-lxc-9.0.0-150500.6.3.1
libvirt-daemon-driver-network-9.0.0-150500.6.3.1
libvirt-daemon-driver-nodedev-9.0.0-150500.6.3.1
libvirt-daemon-driver-nwfilter-9.0.0-150500.6.3.1
libvirt-daemon-driver-qemu-9.0.0-150500.6.3.1
libvirt-daemon-driver-secret-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-core-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-disk-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-gluster-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-logical-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.3.1
libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.3.1
libvirt-daemon-hooks-9.0.0-150500.6.3.1
libvirt-daemon-lxc-9.0.0-150500.6.3.1
libvirt-daemon-qemu-9.0.0-150500.6.3.1
libvirt-daemon-xen-9.0.0-150500.6.3.1
libvirt-devel-9.0.0-150500.6.3.1
libvirt-devel-32bit-9.0.0-150500.6.3.1
libvirt-doc-9.0.0-150500.6.3.1
libvirt-libs-9.0.0-150500.6.3.1
libvirt-lock-sanlock-9.0.0-150500.6.3.1
libvirt-nss-9.0.0-150500.6.3.1
wireshark-plugin-libvirt-9.0.0-150500.6.3.1

Описание

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.


Затронутые продукты
Image SLES15-SP5-SAP-Azure-3P:libvirt-client-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-Azure-3P:libvirt-libs-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-BYOS-Azure:libvirt-client-9.0.0-150500.6.3.1
Image SLES15-SP5-SAP-BYOS-Azure:libvirt-libs-9.0.0-150500.6.3.1

Ссылки
Уязвимость SUSE-SU-2023:2652-1