Описание
Security update for libvirt
This update for libvirt fixes the following issues:
- CVE-2026-18917: remote: Fix integer overflow in RPC handler for virNodeGetFreePages (bsc#1275863)
- CVE-2026-63622: util: virFileChownFiles: do not follow symlinks (bsc#1275264)
- CVE-2026-63623: storage: create images with a private umask during qemu-img create/convert (bsc#12075265)
- CVE-2026-77159: qemu: tpm: Avoid following symlinks when chown'ing log file (bsc#1274946)
- CVE-2026-61477: Reject line breaks in network config (bsc#1274576)
- qemu: Fix invocation of numa-preplace when hugepages requested, but page size not specified (bsc#1266364)
- Add ClearwaterForest CPU model (jsc#PED-16192)
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Server Applications 15 SP7
Ссылки
- Link for SUSE-SU-2026:3939-1
- E-Mail link for SUSE-SU-2026:3939-1
- SUSE Security Ratings
- SUSE Bug 1266364
- SUSE Bug 1274576
- SUSE Bug 1274946
- SUSE Bug 1275264
- SUSE Bug 1275265
- SUSE Bug 1275863
- SUSE CVE CVE-2026-18917 page
- SUSE CVE CVE-2026-61477 page
- SUSE CVE CVE-2026-63622 page
- SUSE CVE CVE-2026-63623 page
- SUSE CVE CVE-2026-77159 page
Описание
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.
Затронутые продукты
Ссылки
- CVE-2026-18917
- SUSE Bug 1275863
Описание
An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.
Затронутые продукты
Ссылки
- CVE-2026-61477
- SUSE Bug 1274576
Описание
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.
Затронутые продукты
Ссылки
- CVE-2026-63622
- SUSE Bug 1275264
Описание
A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was caused by the `qemu-img` utility running with overly permissive file creation settings, allowing any local user to read the full guest disk contents. This vulnerability could lead to sensitive information disclosure from guest virtual machines.
Затронутые продукты
Ссылки
- CVE-2026-63623
- SUSE Bug 1275265
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-77159
- SUSE Bug 1274946