Mageia 2020-0250: libvirt security update
Summary
Advisory text to describe the update.
Wrap lines at ~75 chars.
Updated libvirt packages fix security vulnerability:
It was discovered that libvirt incorrectly handled an active pool without
a target path. A remote attacker could possibly use this issue to cause
libvirt to crash, resulting in a denial of service (CVE-2020-10703).
It was discovered that libvirt incorrectly handled memory when retrieving
certain domain statistics. A remote attacker could possibly use this issue to
cause libvirt to consume resources, resulting in a denial of service
(CVE-2020-12430).
References
- https://bugs.mageia.org/show_bug.cgi?id=26600
- https://ubuntu.com/security/notices/USN-4371-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10703
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12430
Resolution
MGASA-2020-0250 - Updated libvirt packages fix security vulnerability
SRPMS
- 7/core/libvirt-5.5.0-1.1.mga7