An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2 Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2021-1385 Final 1.0 1.0 2021-10-15 Initial 2021-10-15 2021-10-15 openEuler SA Tool V1.0 2021-10-15 libvirt security update An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2. Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support. Security Fix(es): An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.(CVE-2021-3667) A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3631) An update for libvirt is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2. openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. Medium libvirt https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-3667 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-3631 https://nvd.nist.gov/vuln/detail/CVE-2021-3667 https://nvd.nist.gov/vuln/detail/CVE-2021-3631 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 libvirt-daemon-driver-storage-iscsi-direct-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-qemu-6.2.0-13.oe1.aarch64.rpm libvirt-nss-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-qemu-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-kvm-6.2.0-13.oe1.aarch64.rpm libvirt-client-6.2.0-13.oe1.aarch64.rpm libvirt-debuginfo-6.2.0-13.oe1.aarch64.rpm libvirt-admin-6.2.0-13.oe1.aarch64.rpm libvirt-bash-completion-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-logical-6.2.0-13.oe1.aarch64.rpm libvirt-devel-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-interface-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-gluster-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-disk-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-nwfilter-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-secret-6.2.0-13.oe1.aarch64.rpm libvirt-6.2.0-13.oe1.aarch64.rpm libvirt-docs-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-core-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-nodedev-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-scsi-6.2.0-13.oe1.aarch64.rpm libvirt-libs-6.2.0-13.oe1.aarch64.rpm libvirt-debugsource-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-iscsi-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-config-network-6.2.0-13.oe1.aarch64.rpm libvirt-lock-sanlock-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-network-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-rbd-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-config-nwfilter-6.2.0-13.oe1.aarch64.rpm libvirt-wireshark-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-mpath-6.2.0-13.oe1.aarch64.rpm libvirt-daemon-driver-storage-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-kvm-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-iscsi-direct-6.2.0-14.oe1.aarch64.rpm libvirt-bash-completion-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-scsi-6.2.0-14.oe1.aarch64.rpm libvirt-debuginfo-6.2.0-14.oe1.aarch64.rpm libvirt-nss-6.2.0-14.oe1.aarch64.rpm libvirt-wireshark-6.2.0-14.oe1.aarch64.rpm libvirt-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-interface-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-core-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-mpath-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-qemu-6.2.0-14.oe1.aarch64.rpm libvirt-debugsource-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-logical-6.2.0-14.oe1.aarch64.rpm libvirt-docs-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-iscsi-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-config-nwfilter-6.2.0-14.oe1.aarch64.rpm libvirt-libs-6.2.0-14.oe1.aarch64.rpm libvirt-devel-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-secret-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-qemu-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-disk-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-nwfilter-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-rbd-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-storage-gluster-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-nodedev-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-config-network-6.2.0-14.oe1.aarch64.rpm libvirt-daemon-driver-network-6.2.0-14.oe1.aarch64.rpm libvirt-client-6.2.0-14.oe1.aarch64.rpm libvirt-admin-6.2.0-14.oe1.aarch64.rpm libvirt-lock-sanlock-6.2.0-14.oe1.aarch64.rpm libvirt-6.2.0-13.oe1.src.rpm libvirt-6.2.0-14.oe1.src.rpm libvirt-daemon-driver-qemu-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-kvm-6.2.0-13.oe1.x86_64.rpm libvirt-wireshark-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-interface-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-network-6.2.0-13.oe1.x86_64.rpm libvirt-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-core-6.2.0-13.oe1.x86_64.rpm libvirt-admin-6.2.0-13.oe1.x86_64.rpm libvirt-docs-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-secret-6.2.0-13.oe1.x86_64.rpm libvirt-debuginfo-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-nodedev-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-scsi-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-config-nwfilter-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-gluster-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-mpath-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-iscsi-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-config-network-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-nwfilter-6.2.0-13.oe1.x86_64.rpm libvirt-debugsource-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-logical-6.2.0-13.oe1.x86_64.rpm libvirt-bash-completion-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-iscsi-direct-6.2.0-13.oe1.x86_64.rpm libvirt-client-6.2.0-13.oe1.x86_64.rpm libvirt-devel-6.2.0-13.oe1.x86_64.rpm libvirt-nss-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-rbd-6.2.0-13.oe1.x86_64.rpm libvirt-libs-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-qemu-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-storage-disk-6.2.0-13.oe1.x86_64.rpm libvirt-lock-sanlock-6.2.0-13.oe1.x86_64.rpm libvirt-daemon-driver-qemu-6.2.0-14.oe1.x86_64.rpm libvirt-debuginfo-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-qemu-6.2.0-14.oe1.x86_64.rpm libvirt-admin-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-config-network-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-secret-6.2.0-14.oe1.x86_64.rpm libvirt-lock-sanlock-6.2.0-14.oe1.x86_64.rpm libvirt-nss-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-nwfilter-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-iscsi-direct-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-kvm-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-network-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-core-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-rbd-6.2.0-14.oe1.x86_64.rpm libvirt-devel-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-gluster-6.2.0-14.oe1.x86_64.rpm libvirt-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-mpath-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-logical-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-nodedev-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-interface-6.2.0-14.oe1.x86_64.rpm libvirt-docs-6.2.0-14.oe1.x86_64.rpm libvirt-wireshark-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-config-nwfilter-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-scsi-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-iscsi-6.2.0-14.oe1.x86_64.rpm libvirt-client-6.2.0-14.oe1.x86_64.rpm libvirt-debugsource-6.2.0-14.oe1.x86_64.rpm libvirt-bash-completion-6.2.0-14.oe1.x86_64.rpm libvirt-daemon-driver-storage-disk-6.2.0-14.oe1.x86_64.rpm libvirt-libs-6.2.0-14.oe1.x86_64.rpm An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. 2021-10-15 CVE-2021-3667 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 Medium 6.5 AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H libvirt security update 2021-10-15 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity. 2021-10-15 CVE-2021-3631 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 Low 3.0 AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N libvirt security update 2021-10-15 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1385