Fedora 21 Security Update: libvirt-1.2.9.2-1.fc21

Resolved Bugs
1188644 – segfault at 0 ip 00007fed0cb2eb4c sp 00007fecf005fad0 error 4 in libvirt.so.0.1002.11[7fed0ca72000+363000]
1168672 – “libvirtError: Unable to write to ‘/sys/fs/cgroup/cpuset/machine.slice/machine-qemu\x2dinstance\x2d00000002.scope/cpuset.mems’: Device or resource busy”
1172571 – CVE-2014-8131 libvirt: deadlock and segfault in qemuConnectGetAllDomainStats [fedora-all]
1172569 – CVE-2014-8131 libvirt: deadlock and segfault in qemuConnectGetAllDomainStats
1185769 – CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects [fedora-all]
1184431 – CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects
1176179 – CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c [fedora-all]
1176176 – CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c<br
* Rebased to version 1.2.9.2
* CVE-2014-8131: deadlock and segfault in qemuConnectGetAllDomainStats (bz #1172571)
* CVE-2015-0236: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects (bz #1185769)
* CVE-2014-8136: local denial of service in qemu/qemu_driver.c (bz #1176179)
* Fix crash parsing nbd URIs (bz #1188644)
* Fix domain startup failing with ‘strict’ mode in numatune (bz #1168672)

Leave a Reply