stable

libvirt-5.1.0-9.fc30

FEDORA-2019-b2dfb13daf created by crobinso 5 years ago for Fedora 30
  • CVE-2019-10161: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API (bz #1722463, bz #1720115)
  • CVE-2019-10166: virDomainManagedSaveDefineXML API exposed to readonly clients (bz #1722462, bz #1720114)
  • CVE-2019-10167: arbitrary command execution via virConnectGetDomainCapabilities API (bz #1722464, bz #1720117)
  • CVE-2019-10168: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs (bz #1722466, bz #1720118)
  • CVE-2019-3886: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide
  • Cannot start VM with a CBR 2.0 TPM device (bz #1712556)
  • libvirtd does not update VM .xml configurations after virsh snapshot/blockcommit (bz #1722348)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2019-b2dfb13daf

This update has been submitted for testing by crobinso.

5 years ago

This update test gating status has been changed to 'waiting'.

5 years ago

This update test gating status has been changed to 'ignored'.

5 years ago

This update has been pushed to testing.

5 years ago
User Icon atim provided feedback 5 years ago
karma

crobinso edited this update.

5 years ago
User Icon smithp commented & provided feedback 5 years ago
karma

+1

User Icon frantisekz commented & provided feedback 5 years ago
karma

Works fine

User Icon jlanda provided feedback 5 years ago
karma
User Icon alciregi commented & provided feedback 5 years ago
karma

WFM

User Icon kparal commented & provided feedback 5 years ago
karma

my VMs in virt-manager still work fine

This update has reached the stable karma threshold and can be pushed to stable now if the maintainer wishes.

5 years ago
User Icon vinumoses provided feedback 5 years ago
karma

This update has been submitted for stable by crobinso.

5 years ago

This update has been pushed to stable.

5 years ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
7
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
5 years ago
in testing
5 years ago
in stable
5 years ago
modified
5 years ago
BZ#1694880 CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode
0
0
BZ#1696055 CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode [fedora-rawhide]
0
0
BZ#1712556 Cannot start VM with a CBR 2.0 TPM device shows message "Failed to create v1 controller cpu for group: No such file or directory"
0
0
BZ#1720114 CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients
0
0
BZ#1720115 CVE-2019-10161 libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API
0
0
BZ#1720117 CVE-2019-10167 libvirt: arbitrary command execution via virConnectGetDomainCapabilities API
0
0
BZ#1720118 CVE-2019-10168 libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs
0
0
BZ#1722348 libvirtd does not update VM .xml configurations on filesystem after virsh snapshot/blockcommit
0
0
BZ#1722462 CVE-2019-10166 libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients [fedora-all]
0
0
BZ#1722463 CVE-2019-10161 libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API [fedora-all]
0
0
BZ#1722464 CVE-2019-10167 libvirt: arbitrary command execution via virConnectGetDomainCapabilities API [fedora-all]
0
0
BZ#1722466 CVE-2019-10168 libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs [fedora-all]
0
0

Automated Test Results