Security update for libvirt
This update for libvirt fixes the following issues: - CVE-2020-15708: Added a note to libvirtd.conf about polkit auth in SUSE distros (bsc#1174955). - CVE-2020-25637: Fixed a double free in qemuAgentGetInterfaces() (bsc#1177155). - qemu: Adjust max memlock on mdev hotplug (bsc#1177480). - Xen: Don't add dom0 twice on driver reload (bsc#1176430). - virdevmapper: Handle kernel without device-mapper support (bsc#1175465). - Fixed an issue where building was failing (bsc#1175574).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libvirt fixes the following issues: - CVE-2020-15708: Added a note to libvirtd.conf about polkit auth in SUSE distros (bsc#1174955). - CVE-2020-25637: Fixed a double free in qemuAgentGetInterfaces() (bsc#1177155). - qemu: Adjust max memlock on mdev hotplug (bsc#1177480). - Xen: Don't add dom0 twice on driver reload (bsc#1176430). - virdevmapper: Handle kernel without device-mapper support (bsc#1175465). - Fixed an issue where building was failing (bsc#1175574).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1174955
- https://bugzilla.suse.com/1175465
- https://bugzilla.suse.com/1175574
- https://bugzilla.suse.com/1176430
- https://bugzilla.suse.com/1177155
- https://bugzilla.suse.com/1177480
- https://www.suse.com/security/cve/CVE-2020-15708
- https://www.suse.com/security/cve/CVE-2020-25637
- https://www.suse.com/support/update/announcement/2020/suse-su-20203037-1/