RHSA-2020:5040: Moderate: libvirt security and bug fix update
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.Security Fix(es): libvirt: double free in qemuAgentGetInterfaces() in qemuagent.c (CVE-2020-25637) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): libvirt destroying macvtap device of running VM after a failed incoming migration of another VM with same macvtap "target device" (BZ#1868549)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libvirtto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-adminto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-bash-completionto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-clientto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemonto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-config-networkto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-config-nwfilterto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-interfaceto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-lxcto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-networkto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nodedevto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-nwfilterto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-qemuto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-secretto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storageto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-coreto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-diskto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-glusterto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-iscsito a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-logicalto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-mpathto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-rbdto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-driver-storage-scsito a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-kvmto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-daemon-lxcto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-develto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-docsto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-libsto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-lock-sanlockto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-login-shellto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3 - Upgrade
Upgrade
redhat/libvirt-nssto a version that resolves this vulnerability.Fixed in 4.5.0-36.el7_9.3
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5040?
The severity of RHSA-2020:5040 is classified as moderate.
How do I fix RHSA-2020:5040?
To fix RHSA-2020:5040, update the affected libvirt package to version 4.5.0-36.el7_9.3 or higher.
Which versions are affected by RHSA-2020:5040?
RHSA-2020:5040 affects libvirt versions prior to 4.5.0-36.el7_9.3.
What vulnerability does RHSA-2020:5040 address?
RHSA-2020:5040 addresses a double free vulnerability in the libvirt library.
Is there any workaround for RHSA-2020:5040?
No specific workaround is provided for RHSA-2020:5040, and it is recommended to apply the necessary updates.