USN-3909-1: libvirt vulnerability

14 March 2019

libvirt vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 18.10
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS

Summary

libvirt could be made to crash under certain conditions.

Software Description

  • libvirt - Libvirt virtualization toolkit

Details

It was discovered that libvirt incorrectly handled waiting for certain agent events. An attacker inside a guest could possibly use this issue to cause libvirtd to stop responding, resulting in a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.10
libvirt-clients - 4.6.0-2ubuntu3.4
libvirt-daemon - 4.6.0-2ubuntu3.4
libvirt0 - 4.6.0-2ubuntu3.4
Ubuntu 18.04 LTS
libvirt-clients - 4.0.0-1ubuntu8.8
libvirt-daemon - 4.0.0-1ubuntu8.8
libvirt0 - 4.0.0-1ubuntu8.8
Ubuntu 16.04 LTS
libvirt-bin - 1.3.1-1ubuntu10.25
libvirt0 - 1.3.1-1ubuntu10.25

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make all the necessary changes.

References