Oval Definition:oval:org.opensuse.security:def:82840
Revision Date:2019-06-06Version:1
Title:Security update for libvirt (Important)
Description:

This update for libvirt fixes the following issues:

Four new speculative execution information leak issues have been identified in Intel CPUs. (bsc#1111331)

- CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS) - CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS) - CVE-2018-12130: Microarchitectural Load Port Data Sampling (MLPDS) - CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM)

These updates contain the libvirt adjustments, that pass through the new 'md-clear' CPU flag (bsc#1135273).

For more information on this set of vulnerabilities, check out https://www.suse.com/support/kb/doc/?id=7023736

Other security issues fixed:

- CVE-2019-3886: Fixed an information leak which allowed to retrieve the guest hostname under readonly mode (bsc#1131595). - qemu: Add support for using AES secret for SCSI hotplug
Family:unixClass:patch
Status:Reference(s):1111331
1131595
1135273
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2019-11091
CVE-2019-3886
Platform(s):SUSE Linux Enterprise Server 12 SP2-ESPOS
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libvirt-2.0.0-27.54.1 is installed
  • OR libvirt-client-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-config-network-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-config-nwfilter-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-interface-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-libxl-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-lxc-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-network-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-nodedev-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-nwfilter-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-qemu-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-secret-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-driver-storage-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-hooks-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-lxc-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-qemu-2.0.0-27.54.1 is installed
  • OR libvirt-daemon-xen-2.0.0-27.54.1 is installed
  • OR libvirt-doc-2.0.0-27.54.1 is installed
  • OR libvirt-lock-sanlock-2.0.0-27.54.1 is installed
  • OR libvirt-nss-2.0.0-27.54.1 is installed
  • BACK