USN-6763-1: libvirt vulnerability
Published May 7, 2024
·Updated
Martin Širokov discovered that libvirt incorrectly handled certain memory operations. A local attacker could possibly use this issue to access virtproxyd without authorization.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/libvirt-daemon<10.0.0-2ubuntu8.2
10.0.0-2ubuntu8.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libvirt-daemon-system<10.0.0-2ubuntu8.2
10.0.0-2ubuntu8.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libvirt0<10.0.0-2ubuntu8.2
10.0.0-2ubuntu8.2
Ubuntu Ubuntu=24.04
Event History
May 7, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6763-1?
The severity of USN-6763-1 is classified as potentially high due to unauthorized access risks.
2
How do I fix USN-6763-1?
To fix USN-6763-1, upgrade the affected packages to version 10.0.0-2ubuntu8.2 or later.
3
What systems are affected by USN-6763-1?
USN-6763-1 affects Ubuntu 24.04 systems running libvirt packages.
4
Who discovered the vulnerability in USN-6763-1?
The vulnerability in USN-6763-1 was discovered by Martin Širokov.
5
What could an attacker exploit in USN-6763-1?
An attacker could exploit USN-6763-1 to gain unauthorized access to virtproxyd.