RHSA-2019:1580: Important: virt:rhel security update
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.Security Fix(es): libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API (CVE-2019-10161) libvirt: virDomainManagedSaveDefineXML API exposed to readonly clients (CVE-2019-10166) libvirt: arbitrary command execution via virConnectGetDomainCapabilities API (CVE-2019-10167) libvirt: arbitrary command execution via virConnectBaselineHypervisorCPU and virConnectCompareHypervisorCPU APIs (CVE-2019-10168) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/hivexto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-winsupportto a version that resolves this vulnerability.Fixed in 8.0-2.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsito a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libssh2to a version that resolves this vulnerability.Fixed in 1.8.0-7.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirtto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-dbusto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-pythonto a version that resolves this vulnerability.Fixed in 4.5.0-1.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkitto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/netcfto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvmto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/seabiosto a version that resolves this vulnerability.Fixed in 1.11.1-3.module+el8.0.0 - Upgrade
Upgrade
redhat/sgabiosto a version that resolves this vulnerability.Fixed in 0.20170427git-2.module+el8.0.0 - Upgrade
Upgrade
redhat/superminto a version that resolves this vulnerability.Fixed in 5.1.19-8.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-bash-completionto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-inspect-iconsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-javadocto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-man-pages-jato a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-man-pages-ukto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-toolsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-bash-completionto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/seabios-binto a version that resolves this vulnerability.Fixed in 1.11.1-3.module+el8.0.0 - Upgrade
Upgrade
redhat/seavgabios-binto a version that resolves this vulnerability.Fixed in 1.11.1-3.module+el8.0.0 - Upgrade
Upgrade
redhat/sgabios-binto a version that resolves this vulnerability.Fixed in 0.20170427git-2.module+el8.0.0 - Upgrade
Upgrade
redhat/hivex-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/hivex-debugsourceto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/hivex-develto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-benchmarkingto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-benchmarking-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-develto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-gfs2to a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-gobjectto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-gobject-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-gobject-develto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-javato a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-java-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-java-develto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-rescueto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-rsyncto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-tools-cto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-tools-c-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libguestfs-xfsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsi-debuginfoto a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsi-debugsourceto a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsi-develto a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsi-utilsto a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libiscsi-utils-debuginfoto a version that resolves this vulnerability.Fixed in 1.18.0-6.module+el8.0.0 - Upgrade
Upgrade
redhat/libssh2-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-7.module+el8.0.0 - Upgrade
Upgrade
redhat/libssh2-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.0-7.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-adminto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-admin-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-bash-completionto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-clientto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-client-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemonto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-config-networkto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-config-nwfilterto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-interfaceto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-interface-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-networkto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-network-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nodedevto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nodedev-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nwfilterto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nwfilter-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-qemuto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-qemu-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-secretto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-secret-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storageto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-coreto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-core-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-diskto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-disk-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-glusterto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-gluster-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-iscsito a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-iscsi-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-logicalto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-logical-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-mpathto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-mpath-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-rbdto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-rbd-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-scsito a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-scsi-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-daemon-kvmto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-dbus-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-dbus-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-debugsourceto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-develto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-docsto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-libsto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-libs-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-lock-sanlockto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-lock-sanlock-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-nssto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-nss-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-23.3.module+el8.0.0 - Upgrade
Upgrade
redhat/libvirt-python-debugsourceto a version that resolves this vulnerability.Fixed in 4.5.0-1.module+el8.0.0 - Upgrade
Upgrade
redhat/lua-guestfsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/lua-guestfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-basic-pluginsto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-basic-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-develto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-example-pluginsto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-example-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-gzipto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-gzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-python-commonto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-python3to a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-python3-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-vddkto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-vddk-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-xzto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/nbdkit-plugin-xz-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.2-4.module+el8.0.0 - Upgrade
Upgrade
redhat/netcf-debuginfoto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/netcf-debugsourceto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/netcf-develto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/netcf-libsto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/netcf-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.2.8-10.module+el8.0.0 - Upgrade
Upgrade
redhat/perl-hivexto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/perl-hivex-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-hivexto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-hivex-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-libguestfsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-libguestfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-libvirtto a version that resolves this vulnerability.Fixed in 4.5.0-1.module+el8.0.0 - Upgrade
Upgrade
redhat/python3-libvirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-1.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-guest-agentto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-guest-agent-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-imgto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-img-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-curlto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-curl-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-glusterto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-gluster-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-iscsito a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-iscsi-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-rbdto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-rbd-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-sshto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-block-ssh-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-commonto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-common-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-coreto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/qemu-kvm-debugsourceto a version that resolves this vulnerability.Fixed in 2.12.0-64.module+el8.0.0 - Upgrade
Upgrade
redhat/ruby-hivexto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/ruby-hivex-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.15-6.module+el8.0.0 - Upgrade
Upgrade
redhat/ruby-libguestfsto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/ruby-libguestfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/supermin-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.19-8.module+el8.0.0 - Upgrade
Upgrade
redhat/supermin-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.19-8.module+el8.0.0 - Upgrade
Upgrade
redhat/supermin-develto a version that resolves this vulnerability.Fixed in 5.1.19-8.module+el8.0.0 - Upgrade
Upgrade
redhat/virt-dibto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/virt-dib-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/virt-p2v-makerto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/virt-v2vto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0 - Upgrade
Upgrade
redhat/virt-v2v-debuginfoto a version that resolves this vulnerability.Fixed in 1.38.4-10.1.module+el8.0.0
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:1580?
The severity of RHSA-2019:1580 is rated as moderate due to arbitrary file read and execute vulnerabilities in libvirt.
How do I fix RHSA-2019:1580?
To fix RHSA-2019:1580, you should upgrade the affected packages to the latest available versions provided in the advisory.
Which packages are affected by RHSA-2019:1580?
Affected packages in RHSA-2019:1580 include libvirt, libguestfs, hivex, and several others specified in the advisory.
What is the impact of not addressing RHSA-2019:1580?
Not addressing RHSA-2019:1580 could potentially allow unauthorized access to sensitive files in a virtualization environment.
Is there a workaround for RHSA-2019:1580?
Currently, there are no known workarounds for RHSA-2019:1580, so upgrading is necessary to mitigate the vulnerabilities.