Debian Security Advisory
DSA-4137-1 libvirt -- security update
- Date Reported:
- 14 Mar 2018
- Affected Packages:
- libvirt
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-1064, CVE-2018-5748, CVE-2018-6764.
- More information:
-
Several vulnerabilities were discovered in Libvirt, a virtualisation abstraction library:
- CVE-2018-1064
Daniel Berrange discovered that the QEMU guest agent performed insufficient validation of incoming data, which allows a privileged user in the guest to exhaust resources on the virtualisation host, resulting in denial of service.
- CVE-2018-5748
Daniel Berrange and Peter Krempa discovered that the QEMU monitor was susceptible to denial of service by memory exhaustion. This was already fixed in Debian stretch and only affects Debian jessie.
- CVE-2018-6764
Pedro Sampaio discovered that LXC containers detected the hostname insecurely. This only affects Debian stretch.
For the oldstable distribution (jessie), these problems have been fixed in version 1.2.9-9+deb8u5.
For the stable distribution (stretch), these problems have been fixed in version 3.0.0-4+deb9u3.
We recommend that you upgrade your libvirt packages.
For the detailed security status of libvirt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libvirt
- CVE-2018-1064