Security update for libvirt
This update for libvirt fixes the following issues: Security issues fixed: - CVE-2017-5715: Fixes for speculative side channel attacks aka 'SpectreAttack' (var2) (bsc#1079869). - CVE-2018-1064: Fixed denial of service when reading from guest agent (bsc#1083625). - CVE-2018-5748: Fixed possible denial of service when reading from QEMU monitor (bsc#1076500). Non-security issues fixed: - bsc#1083061: Fixed 'dumpxml --migratable' exports domain id in output on SLES11 SP4. - bsc#1055365: Improve performance when listing hundreds of interfaces.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libvirt fixes the following issues: Security issues fixed: - CVE-2017-5715: Fixes for speculative side channel attacks aka 'SpectreAttack' (var2) (bsc#1079869). - CVE-2018-1064: Fixed denial of service when reading from guest agent (bsc#1083625). - CVE-2018-5748: Fixed possible denial of service when reading from QEMU monitor (bsc#1076500). Non-security issues fixed: - bsc#1083061: Fixed 'dumpxml --migratable' exports domain id in output on SLES11 SP4. - bsc#1055365: Improve performance when listing hundreds of interfaces.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1055365
- https://bugzilla.suse.com/1076500
- https://bugzilla.suse.com/1079869
- https://bugzilla.suse.com/1083061
- https://bugzilla.suse.com/1083625
- https://www.suse.com/security/cve/CVE-2017-5715
- https://www.suse.com/security/cve/CVE-2018-1064
- https://www.suse.com/security/cve/CVE-2018-5748
- https://www.suse.com/support/update/announcement/2018/suse-su-20180838-1/