Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2024:1100-1 Moderate: DoS Risk Fixed in libvirt

opensuse
Calendar Grey April 8, 2024
Dist Opensuse Esm H88
Enhancements in libvirt tackle major vulnerabilities such as CVE-2024-2494 aimed at averting possible DoS incidents. Discover the details!
This update for libvirt fixes the following issues: CVE-2024-2494: Add a check for negative array lengths before allocation to prevent potential DoS

Description

This update for libvirt fixes the following issues:

* CVE-2024-2494: Add a check for negative array lengths before allocation to

prevent potential DoS. (bsc#1221815)

The following non-security bug was fixed:

* Avoid memleak in virNodeDeviceGetPCIVPDDynamicCap() (bsc#1221749).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2024-1100=1

* openSUSE Leap Micro 5.3

zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1100=1

* openSUSE Leap Micro 5.4

zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1100=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2024-1100=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2024-1100=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2024-1100=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2024-1100=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-1100=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

zypper in -t patch...

Read the Full Advisory

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

* libvirt-daemon-driver-lxc-debuginfo-8.0.0-150400.7.11.2

* libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.11.2

* libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.11.2

* libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.11.2

* libvirt-daemon-lxc-8.0.0-150400.7.11.2

* libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.11.2

* wireshark-plugin-libvirt-debuginfo-8.0.0-150400.7.11.2

* libvirt-nss-debuginfo-8.0.0-150400.7.11.2

* libvirt-client-8.0.0-150400.7.11.2

* libvirt-libs-8.0.0-150400.7.11.2

* libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.11.2

* libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.11.2

* libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.11.2

* libvirt-lock-sanlock-8.0.0-150400.7.11.2

* libvirt-daemon-driver-qemu-8.0.0-150400.7.11.2

* libvirt-daemon-driver-storage-core-8.0.0-150400.7.11.2

* libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.11.2

*...

Read the Full Advisory

References

* bsc#1221749

* bsc#1221815

## References:

* https://www.suse.com/security/cve/CVE-2024-2494.html

* https://bugzilla.suse.com/show_bug.cgi?id=1221749

* https://bugzilla.suse.com/show_bug.cgi?id=1221815

Announcement ID: SUSE-SU-2024:1100-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here