First published: Tue Jun 19 2018(Updated: )
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.<br>Security Fix(es):<br><li> libvirt: Resource exhaustion via qemuMonitorIORead() method (CVE-2018-5748)</li> <li> libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent (CVE-2018-1064)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>The CVE-2018-5748 issue was discovered by Daniel P. Berrange (Red Hat) and Peter Krempa (Red Hat), and the CVE-2018-1064 issue was discovered by Daniel P. Berrange (Red Hat).<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.10 Release Notes and Red Hat Enterprise Linux 6.10 Technical Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libvirt | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-client | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-client | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-debuginfo | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-debuginfo | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-devel | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-devel | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-lock-sanlock | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-python | <0.10.2-64.el6 | 0.10.2-64.el6 |
redhat/libvirt-python | <0.10.2-64.el6 | 0.10.2-64.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.