CESA-2018:1929 -- centos 6 libvirtID: oval:org.secpod.oval:def:204842 | Date: (C)2019-01-03 (M)2024-01-29 |
Class: PATCH | Family: unix |
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems. Security Fix: * libvirt: Resource exhaustion via qemuMonitorIORead method * libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. The CVE-2018-5748 issue was discovered by Daniel P. Berrange and Peter Krempa , and the CVE-2018-1064 issue was discovered by Daniel P. Berrange . Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 6.10 Release Notes and Red Hat Enterprise Linux 6.10 Technical Notes linked from the References section.