Rapid7 Vulnerability & Exploit Database

Oracle Linux: (CVE-2019-10166) (Multiple Advisories): libvirt security update

Back to Search

Oracle Linux: (CVE-2019-10166) (Multiple Advisories): libvirt security update

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
06/21/2019
Created
06/25/2019
Added
06/23/2019
Modified
07/11/2019

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From ELSA-2019-4714:

[5.0.0-9.el7] - qemu: remove cpuhostmask and cpuguestmask from virCaps structure (Wim ten Have) [Orabug: 29956508] [5.0.0-8.el7] - api: disallow virDomainSaveImageGetXMLDesc on read-only connections (Jan Tomko) [Orabug: 29955742] {CVE-2019-10161} - domain: Define explicit flags for saved image xml (Eric Blake) [Orabug: 29955742] - api: disallow virDomainManagedSaveDefineXML on read-only connections (Jan Tomko) [Orabug: 29955742] {CVE-2019-10166} - api: disallow virConnectGetDomainCapabilities on read-only connections (Jan Tomko) [Orabug: 29955742] {CVE-2019-10167} - api: disallow virConnect*HypervisorCPU on read-only connections (Jan Tomko) [Orabug: 29955742] {CVE-2019-10168} [5.0.0-7.el7] - cpu_map: Define md-clear CPUID bit (Jiri Denemark) [Orabug: 29874181] {CVE-2018-12126} {CVE-2018-12127} {CVE-2018-12130} {CVE-2019-11091} [5.0.0-6.el7] - qemu: Driver change adding private lock to auto-tune hugepages (Wim ten Have) [Orabug: 29809943] [5.0.0-5.el7] - qemu: disable setmem change requests for vNUMA targets (Wim ten Have) [Orabug: 29797366] - domain: Disable memballoon memory configuration support for vNUMA guests (Wim ten Have) [Orabug: 29797366] - qemu: Driver change to target for vNUMA setmaxmem change request (Wim ten Have) [Orabug: 29749852] - domain: Add domain memory config support for vNUMA guests (Wim ten Have) [Orabug: 29749852] - logging: restrict sockets to mode 0600 (Daniel P. Berrange) [Orabug: 29861433] {CVE-2019-10132} - locking: restrict sockets to mode 0600 (Daniel P. Berrange) [Orabug: 29861433] {CVE-2019-10132} - admin: reject clients unless their UID matches the current UID (Daniel P. Berrange) [Orabug: 29861433] {CVE-2019-10132}

Solution(s)

  • oracle-linux-upgrade-libvirt
  • oracle-linux-upgrade-libvirt-admin
  • oracle-linux-upgrade-libvirt-bash-completion
  • oracle-linux-upgrade-libvirt-client
  • oracle-linux-upgrade-libvirt-daemon
  • oracle-linux-upgrade-libvirt-daemon-config-network
  • oracle-linux-upgrade-libvirt-daemon-config-nwfilter
  • oracle-linux-upgrade-libvirt-daemon-driver-interface
  • oracle-linux-upgrade-libvirt-daemon-driver-lxc
  • oracle-linux-upgrade-libvirt-daemon-driver-network
  • oracle-linux-upgrade-libvirt-daemon-driver-nodedev
  • oracle-linux-upgrade-libvirt-daemon-driver-nwfilter
  • oracle-linux-upgrade-libvirt-daemon-driver-qemu
  • oracle-linux-upgrade-libvirt-daemon-driver-secret
  • oracle-linux-upgrade-libvirt-daemon-driver-storage
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-core
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-disk
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-gluster
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-iscsi
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-logical
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-mpath
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-rbd
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-scsi
  • oracle-linux-upgrade-libvirt-daemon-kvm
  • oracle-linux-upgrade-libvirt-daemon-lxc
  • oracle-linux-upgrade-libvirt-daemon-qemu
  • oracle-linux-upgrade-libvirt-devel
  • oracle-linux-upgrade-libvirt-docs
  • oracle-linux-upgrade-libvirt-libs
  • oracle-linux-upgrade-libvirt-lock-sanlock
  • oracle-linux-upgrade-libvirt-login-shell
  • oracle-linux-upgrade-libvirt-nss

References

  • oracle-linux-upgrade-libvirt
  • oracle-linux-upgrade-libvirt-admin
  • oracle-linux-upgrade-libvirt-bash-completion
  • oracle-linux-upgrade-libvirt-client
  • oracle-linux-upgrade-libvirt-daemon
  • oracle-linux-upgrade-libvirt-daemon-config-network
  • oracle-linux-upgrade-libvirt-daemon-config-nwfilter
  • oracle-linux-upgrade-libvirt-daemon-driver-interface
  • oracle-linux-upgrade-libvirt-daemon-driver-lxc
  • oracle-linux-upgrade-libvirt-daemon-driver-network
  • oracle-linux-upgrade-libvirt-daemon-driver-nodedev
  • oracle-linux-upgrade-libvirt-daemon-driver-nwfilter
  • oracle-linux-upgrade-libvirt-daemon-driver-qemu
  • oracle-linux-upgrade-libvirt-daemon-driver-secret
  • oracle-linux-upgrade-libvirt-daemon-driver-storage
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-core
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-disk
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-gluster
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-iscsi
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-logical
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-mpath
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-rbd
  • oracle-linux-upgrade-libvirt-daemon-driver-storage-scsi
  • oracle-linux-upgrade-libvirt-daemon-kvm
  • oracle-linux-upgrade-libvirt-daemon-lxc
  • oracle-linux-upgrade-libvirt-daemon-qemu
  • oracle-linux-upgrade-libvirt-devel
  • oracle-linux-upgrade-libvirt-docs
  • oracle-linux-upgrade-libvirt-libs
  • oracle-linux-upgrade-libvirt-lock-sanlock
  • oracle-linux-upgrade-libvirt-login-shell
  • oracle-linux-upgrade-libvirt-nss

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;