FlawAtlas
Search the atlas
SUSE-SU-2020:2237-1 Not scored

Security update for libvirt

This update for libvirt fixes the following issues: - CVE-2020-14339: Don't leak /dev/mapper/control into QEMU. Use ioctl's to obtain the dependency tree of disks and drop use of libdevmapper. - bsc#1161883, bsc#1174458 - qemu: Setup emulator thread and cpuset.mems before exec - bsc#1171946 - libxl: Normalize MAC address in device conf on netdev hotplug - bsc#1172052 - spec: Use a functional requires instead of explicit version requires for the new memory-related libxl APIs - bsc#1167007

Exploit probability Not scored
Published August 14, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP1 libvirt
SUSE:Linux Enterprise Module for Server Applications 15 SP1 libvirt

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:2237-1

This update for libvirt fixes the following issues: - CVE-2020-14339: Don't leak /dev/mapper/control into QEMU. Use ioctl's to obtain the dependency tree of disks and drop use of libdevmapper. - bsc#1161883, bsc#1174458 - qemu: Setup emulator thread and cpuset.mems before exec - bsc#1171946 - libxl: Normalize MAC address in device conf on netdev hotplug - bsc#1172052 - spec: Use a functional requires instead of explicit version requires for the new memory-related libxl APIs - bsc#1167007

View original source

05 / REFERENCES

Further evidence