This update for libvirt fixes the following issues:
Security issues fixed:
- CVE-2021-3631: fix SELinux label generation logic (bsc#1187871)
- CVE-2021-3667: Unlock object on ACL fail in
storagePoolLookupByTargetPath (bsc#1188843)
Non-security issues fixed:
- virtlockd: Don't report error if lockspace exists (bsc#1184253)
- Don't forcibly remove '--listen' arg from /etc/sysconfig/libvirtd. Add
'--timeout 120' if '--listen' is not specified. (bsc#1188232)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-2812=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
libvirt-7.1.0-6.5.1
libvirt-admin-7.1.0-6.5.1
libvirt-admin-debuginfo-7.1.0-6.5.1
libvirt-client-7.1.0-6.5.1
libvirt-client-debuginfo-7.1.0-6.5.1
libvirt-daemon-7.1.0-6.5.1
libvirt-daemon-config-network-7.1.0-6.5.1
libvirt-daemon-config-nwfilter-7.1.0-6.5.1
libvirt-daemon-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-interface-7.1.0-6.5.1
libvirt-daemon-driver-interface-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-lxc-7.1.0-6.5.1
libvirt-daemon-driver-lxc-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-network-7.1.0-6.5.1
libvirt-daemon-driver-network-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-nodedev-7.1.0-6.5.1
libvirt-daemon-driver-nodedev-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-nwfilter-7.1.0-6.5.1
libvirt-daemon-driver-nwfilter-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-qemu-7.1.0-6.5.1
libvirt-daemon-driver-qemu-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-secret-7.1.0-6.5.1
libvirt-daemon-driver-secret-debuginfo-7.1.0-6.5.1
libvirt-daemon-driver-storag...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2021-3631.html
https://www.suse.com/security/cve/CVE-2021-3667.html
https://bugzilla.suse.com/1184253
https://bugzilla.suse.com/1187871
https://bugzilla.suse.com/1188232
https://bugzilla.suse.com/1188843
Get the latest Linux and open source security news straight to your inbox.