An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2021-1385
Final
1.0
1.0
2021-10-15
Initial
2021-10-15
2021-10-15
openEuler SA Tool V1.0
2021-10-15
libvirt security update
An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.
Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.
Security Fix(es):
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.(CVE-2021-3667)
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3631)
An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.
openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
Medium
libvirt
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-3667
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-3631
https://nvd.nist.gov/vuln/detail/CVE-2021-3667
https://nvd.nist.gov/vuln/detail/CVE-2021-3631
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
libvirt-daemon-driver-storage-iscsi-direct-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-qemu-6.2.0-13.oe1.aarch64.rpm
libvirt-nss-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-qemu-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-kvm-6.2.0-13.oe1.aarch64.rpm
libvirt-client-6.2.0-13.oe1.aarch64.rpm
libvirt-debuginfo-6.2.0-13.oe1.aarch64.rpm
libvirt-admin-6.2.0-13.oe1.aarch64.rpm
libvirt-bash-completion-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-logical-6.2.0-13.oe1.aarch64.rpm
libvirt-devel-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-interface-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-gluster-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-disk-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-nwfilter-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-secret-6.2.0-13.oe1.aarch64.rpm
libvirt-6.2.0-13.oe1.aarch64.rpm
libvirt-docs-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-core-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-nodedev-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-scsi-6.2.0-13.oe1.aarch64.rpm
libvirt-libs-6.2.0-13.oe1.aarch64.rpm
libvirt-debugsource-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-iscsi-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-config-network-6.2.0-13.oe1.aarch64.rpm
libvirt-lock-sanlock-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-network-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-rbd-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-config-nwfilter-6.2.0-13.oe1.aarch64.rpm
libvirt-wireshark-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-mpath-6.2.0-13.oe1.aarch64.rpm
libvirt-daemon-driver-storage-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-kvm-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-iscsi-direct-6.2.0-14.oe1.aarch64.rpm
libvirt-bash-completion-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-scsi-6.2.0-14.oe1.aarch64.rpm
libvirt-debuginfo-6.2.0-14.oe1.aarch64.rpm
libvirt-nss-6.2.0-14.oe1.aarch64.rpm
libvirt-wireshark-6.2.0-14.oe1.aarch64.rpm
libvirt-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-interface-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-core-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-mpath-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-qemu-6.2.0-14.oe1.aarch64.rpm
libvirt-debugsource-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-logical-6.2.0-14.oe1.aarch64.rpm
libvirt-docs-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-iscsi-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-config-nwfilter-6.2.0-14.oe1.aarch64.rpm
libvirt-libs-6.2.0-14.oe1.aarch64.rpm
libvirt-devel-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-secret-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-qemu-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-disk-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-nwfilter-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-rbd-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-storage-gluster-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-nodedev-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-config-network-6.2.0-14.oe1.aarch64.rpm
libvirt-daemon-driver-network-6.2.0-14.oe1.aarch64.rpm
libvirt-client-6.2.0-14.oe1.aarch64.rpm
libvirt-admin-6.2.0-14.oe1.aarch64.rpm
libvirt-lock-sanlock-6.2.0-14.oe1.aarch64.rpm
libvirt-6.2.0-13.oe1.src.rpm
libvirt-6.2.0-14.oe1.src.rpm
libvirt-daemon-driver-qemu-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-kvm-6.2.0-13.oe1.x86_64.rpm
libvirt-wireshark-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-interface-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-network-6.2.0-13.oe1.x86_64.rpm
libvirt-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-core-6.2.0-13.oe1.x86_64.rpm
libvirt-admin-6.2.0-13.oe1.x86_64.rpm
libvirt-docs-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-secret-6.2.0-13.oe1.x86_64.rpm
libvirt-debuginfo-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-nodedev-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-scsi-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-config-nwfilter-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-gluster-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-mpath-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-config-network-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-nwfilter-6.2.0-13.oe1.x86_64.rpm
libvirt-debugsource-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-logical-6.2.0-13.oe1.x86_64.rpm
libvirt-bash-completion-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-direct-6.2.0-13.oe1.x86_64.rpm
libvirt-client-6.2.0-13.oe1.x86_64.rpm
libvirt-devel-6.2.0-13.oe1.x86_64.rpm
libvirt-nss-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-rbd-6.2.0-13.oe1.x86_64.rpm
libvirt-libs-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-qemu-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-storage-disk-6.2.0-13.oe1.x86_64.rpm
libvirt-lock-sanlock-6.2.0-13.oe1.x86_64.rpm
libvirt-daemon-driver-qemu-6.2.0-14.oe1.x86_64.rpm
libvirt-debuginfo-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-qemu-6.2.0-14.oe1.x86_64.rpm
libvirt-admin-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-config-network-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-secret-6.2.0-14.oe1.x86_64.rpm
libvirt-lock-sanlock-6.2.0-14.oe1.x86_64.rpm
libvirt-nss-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-nwfilter-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-direct-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-kvm-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-network-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-core-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-rbd-6.2.0-14.oe1.x86_64.rpm
libvirt-devel-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-gluster-6.2.0-14.oe1.x86_64.rpm
libvirt-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-mpath-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-logical-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-nodedev-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-interface-6.2.0-14.oe1.x86_64.rpm
libvirt-docs-6.2.0-14.oe1.x86_64.rpm
libvirt-wireshark-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-config-nwfilter-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-scsi-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-iscsi-6.2.0-14.oe1.x86_64.rpm
libvirt-client-6.2.0-14.oe1.x86_64.rpm
libvirt-debugsource-6.2.0-14.oe1.x86_64.rpm
libvirt-bash-completion-6.2.0-14.oe1.x86_64.rpm
libvirt-daemon-driver-storage-disk-6.2.0-14.oe1.x86_64.rpm
libvirt-libs-6.2.0-14.oe1.x86_64.rpm
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
2021-10-15
CVE-2021-3667
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
Medium
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
libvirt security update
2021-10-15
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
2021-10-15
CVE-2021-3631
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
Low
3.0
AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
libvirt security update
2021-10-15
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385