Security update for libvirt
This update for libvirt fixes the following issues: Security issues fixed: - CVE-2020-10703: Fixed a daemon crash caused by pools without target paths (bsc#1168683). - CVE-2020-12430: Fixed a memory leak in qemuDomainGetStatsIOThread (bsc#1170765). Non-security issues fixed: - Support setting credit2 scheduler parameters for xen (bsc#1162160). - Enable use of newer libxl APIs for retrieving memory statistics (bsc#1157490, bsc#1167007). - Create multipath targets for qemu PR (bsc#1161883).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libvirt fixes the following issues: Security issues fixed: - CVE-2020-10703: Fixed a daemon crash caused by pools without target paths (bsc#1168683). - CVE-2020-12430: Fixed a memory leak in qemuDomainGetStatsIOThread (bsc#1170765). Non-security issues fixed: - Support setting credit2 scheduler parameters for xen (bsc#1162160). - Enable use of newer libxl APIs for retrieving memory statistics (bsc#1157490, bsc#1167007). - Create multipath targets for qemu PR (bsc#1161883).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1157490
- https://bugzilla.suse.com/1161883
- https://bugzilla.suse.com/1162160
- https://bugzilla.suse.com/1167007
- https://bugzilla.suse.com/1168683
- https://bugzilla.suse.com/1170765
- https://www.suse.com/security/cve/CVE-2020-10703
- https://www.suse.com/security/cve/CVE-2020-12430
- https://www.suse.com/support/update/announcement/2020/suse-su-20201277-1/