Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

openSUSE 15.5 SUSE-SU-2023:3043-1 Moderate: libvirt Denial of Service

opensuse
Calendar Grey July 31, 2023
Scroller Opensuse
A security patch for libvirt addresses a moderate severity denial of service vulnerability. Please refer to the installation guide for further details.
This update for libvirt fixes the following issues: Security fixes:

Description

This update for libvirt fixes the following issues:

Security fixes:

* CVE-2023-3750: Fixed mproper locking in virStoragePoolObjListSearch that may

lead to denial of service (bsc#1213447).

Other fixes:

* build library with support for modular daemons (bsc#1213352).

Patch

## Patch Instructions:

To install this SUSE Moderate update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch SUSE-2023-3043=1 openSUSE-SLE-15.5-2023-3043=1

* Basesystem Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3043=1

* Server Applications Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2023-3043=1

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586)

* libvirt-daemon-driver-nwfilter-9.0.0-150500.6.11.1

* libvirt-client-9.0.0-150500.6.11.1

* libvirt-9.0.0-150500.6.11.1

* libvirt-daemon-9.0.0-150500.6.11.1

* libvirt-client-qemu-9.0.0-150500.6.11.1

* libvirt-devel-9.0.0-150500.6.11.1

* libvirt-daemon-driver-storage-core-9.0.0-150500.6.11.1

* libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.11.1

* libvirt-daemon-hooks-9.0.0-150500.6.11.1

* libvirt-daemon-qemu-9.0.0-150500.6.11.1

* libvirt-daemon-config-nwfilter-9.0.0-150500.6.11.1

* libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.11.1

* libvirt-daemon-debuginfo-9.0.0-150500.6.11.1

* wireshark-plugin-libvirt-9.0.0-150500.6.11.1

* libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.11.1

* libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.11.1

* libvirt-daemon-driver-storage-gluster-debuginfo-9.0.0-150500.6.11.1

* libvirt-daemon-driver-storage-logical-9.0.0-150500.6.11.1

* libvirt-nss-9.0.0-150500.6.11.1

*...

Read the Full Advisory

References

* #1213352

* #1213447

## References:

* https://www.suse.com/security/cve/CVE-2023-3750.html

* https://bugzilla.suse.com/show_bug.cgi?id=1213352

* https://bugzilla.suse.com/show_bug.cgi?id=1213447

Announcement ID: SUSE-SU-2023:3043-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.