Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Red Hat: RHSA-2021:2538-01 Important: Libguestfs Security Flaw

red hat
Calendar Grey November 3, 2016
Scroller Redhat
A new update has been released for Red Hat Enterprise Linux that resolves security vulnerabilities associated with libguestfs and virt-p2v, classified with a moderate severity rating.
An update for libguestfs and virt-p2v is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The libguestfs packages contain a library, which is used for accessing and modifying virtual machine (VM) disk images.
Virt-p2v is a tool for conversion of a physical server to a virtual guest.
The following packages have been upgraded to a newer upstream version: libguestfs (1.32.7), virt-p2v (1.32.7). (BZ#1218766)
Security Fix(es):
* An integer conversion flaw was found in the way OCaml's String handled its length. Certain operations on an excessively long String could trigger a buffer overflow or result in an information leak. (CVE-2015-8869)
Note: The libguestfs packages in this advisory were rebuilt with a fixed version of OCaml to address this issue.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2015-8869 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: libguestfs-1.32.7-3.el7.src.rpm
noarch: libguestfs-inspect-icons-1.32.7-3.el7.noarch.rpm libguestfs-tools-1.32.7-3.el7.noarch.rpm
x86_64: libguestfs-1.32.7-3.el7.x86_64.rpm libguestfs-debuginfo-1.32.7-3.el7.x86_64.rpm libguestfs-java-1.32.7-3.el7.x86_64.rpm libguestfs-tools-c-1.32.7-3.el7.x86_64.rpm libguestfs-xfs-1.32.7-3.el7.x86_64.rpm perl-Sys-Guestfs-1.32.7-3.el7.x86_64.rpm python-libguestfs-1.32.7-3.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
noarch: libguestfs-bash-completion-1.32.7-3.el7.noarch.rpm libguestfs-gobject-doc-1.32.7-3.el7.noarch.rpm libguestfs-javadoc-1.32.7-3.el7.noarch.rpm libguestfs-man-pages-ja-1.32.7-3.el7.noarch.rpm libguestfs-man-pages-uk-1.32.7-3.el7.noarch.rpm
x86_64: libguestfs-debuginfo-1.32.7-3.el7.x86_64.rpm libguestfs-devel-1.32.7-3.el7.x86_64.rpm libguestfs-gfs2-1.32.7-3.el7.x86_64.rpm libguestfs-gobject-1.32.7-3.el7.x86_64.rpm libguestfs-gobject-devel-1.32.7-3.el7.x86_64.rpm libguestfs-java-devel-1.32.7-3.el7.x86_64.rpm libguestfs-rescue-1.32.7-3.el7.x86_64.rpm libguestfs-rsync-1.32.7-3.el7.x86_64.rpm lua-guestfs-1.32.7-3.el7.x86_64.rpm ocaml-libguestfs-1.32.7-3.el7.x86_64.rpm ocaml-libguestfs-devel-1.32.7-3.el7.x86_64.rpm ruby-libguestfs-1.32.7-3.el7.x86_64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2016:2576-02
Product: Red Hat Enterprise Linux
Issue date: 2016-11-03

Topic

An update for libguestfs and virt-p2v is now available for Red HatEnterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Server (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64

Bugs Fixed

855058 - RFE: virt-p2v: display more information about storage devices

1064041 - virt-sparsify fails if a btrfs filesystem contains readonly snapshots

1099976 - virt-builder gives GPG warning message with gnupg2

1156298 - Remove files in package libguestfs-bash-completion, these files are bash completion files, some of the virt tool completion are already implement in another file, so can remove its completion file

1164708 - set-label can only set <=127 bytes for btrfs and <=126 bytes for ntfs filesystem which not meet the help message. Also for ntfs it should give a warning message when the length >128 bytes

1166057 - btrfs filesystem will not work well if you create the filesystem with multiple disks at the same time, such as: mkfs-btrfs "/dev/sda1 /dev/sdb1"

1167916 - P2V: invalid conversion server prints unexpected end of file waiting for password prompt.

1173695 - RFE: allow passing in a pre-opened libvirt connection from python

1174551 - "lstatnslist" and "lstatlist" don't give an error if the API is used wrongly

1176801 - File /etc/sysconfig/kernel isn't updated when convert XenPV guest with regular kernel installed

1180769 - Security context on image file gets reset

1190669 - Support virt-v2v conversion of Windows > 7

1213324 - virt-v2v: warning: unknown guest operating system: windows windows 6.3 when converting win8,win8.1,win2012,win2012R2,win10 to rhev

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.