Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2019:0948-1 Moderate: Libvirt Security Issue Enables Remote DoS

suse
Calendar Grey April 15, 2019
Dist Suse Esm H88
SUSE Security Patch rectifies issues in libvirt, strengthening protection measures for its clients.
An update that solves two vulnerabilities and has 6 fixes is now available

Summary

This update for libvirt fixes the following issues: Security issue fixed: - CVE-2019-3840: Fixed a null pointer dereference vulnerability in virJSONValueObjectHasKey function which could have resulted in a remote denial of service via the guest agent (bsc#1127458). - CVE-2019-3886: Fixed an information leak which allowed to retrieve the guest hostname under readonly mode (bsc#1131595). Other issues addressed: - libxl: support Xen's max_grant_frames setting with maxGrantFrames attribute on the xenbus controller (bsc#1126325). - conf: added new 'xenbus' controller type - util: skip RDMA detection for non-PCI network devices (bsc#1112182). - qemu: don't use CAP_DAC_OVERRIDE capability if non-root (bsc#1125665). - qemu: fix issues related to restricted permissions on /dev/sev(bsc#1102604).

References

#1081516 #1102604 #1112182 #1120813 #1125665

#1126325 #1127458 #1131595

Cross- CVE-2019-3840 CVE-2019-3886

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

https://www.suse.com/security/cve/CVE-2019-3840.html

https://www.suse.com/security/cve/CVE-2019-3886.html

https://bugzilla.suse.com/1081516

https://bugzilla.suse.com/1102604

https://bugzilla.suse.com/1112182

https://bugzilla.suse.com/1120813

https://bugzilla.suse.com/1125665

https://bugzilla.suse.com/1126325

https://bugzilla.suse.com/1127458

https://bugzilla.suse.com/1131595

Announcement ID: SUSE-SU-2019:0948-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here