REDHAT-BUG-709769: Medium severity libvirt vulnerability
Regression introduced in commit d6623003 (v0.8.8) - using the wrong sizeof operand meant that security manager private data was overlaying the allowDiskFOrmatProbing member of struct virSecurityManager. This reopens disk probing, which was supposed to be prevented by the solution to CVE-2010-2238.
Upstream patch: https://www.redhat.com/archives/libvir-list/2011-May/msg01935.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-709769?
The severity of REDHAT-BUG-709769 is significant as it reopens disk probing vulnerabilities in libvirt.
How do I fix REDHAT-BUG-709769?
To fix REDHAT-BUG-709769, update to the latest version of libvirt where this regression has been addressed.
What components are affected by REDHAT-BUG-709769?
REDHAT-BUG-709769 affects the libvirt component developed by Red Hat.
What does REDHAT-BUG-709769 mean for security management?
REDHAT-BUG-709769 means that private data in the security manager is improperly handled, potentially allowing unauthorized disk probing.
Was REDHAT-BUG-709769 caused by a recent change?
Yes, REDHAT-BUG-709769 was introduced by a regression in a commit made in version 0.8.8 of libvirt.