libvirt-0.10.2-29.5.0.1.AXS4

エラータID: AXSA:2014-076:01

Release date: 
Tuesday, March 18, 2014 - 20:25
Subject: 
libvirt-0.10.2-29.5.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.

Security issues fixed with this release:

• CVE-2013-6458
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

• CVE-2014-1447
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

Fixed bugs:

• Previously, the VLAN tag for a hostdev-based network was not set properly in the hardware device. This has been fixed and VLAN tags set in the network definition are now transferred to devices as they are assigned to guests.

• A previous fix left cases where locks were not cleaned up. This could make libvirtd crash when migrating to a file. This has been fixed.

• Made the libvirt-guests init script LSB compliant so that scripts relying on the service status run as expected.

• Previously, the virDomainDeviceUpdateFlags() function in libvirt allowed to update some configuration on a running domain. But a missing implementation prevented the QoS to be changed when updating the Network Interface Controller. This has been fixed.

• Previously, libvirt sometimes failed to detect that a domain had already been started so when two clients tried to start the same transient domain, more than one QEMU process could run for the same domain. this has been fixed and only one QEMU process will run for the same domain.

• Fixed a regression in event de-registration that triggered the following error message:

Error "libvirt: XML-RPC error : internal error: domain event 0 not registered"

• Previously, the libvirt python bindings did not distinguish between a block job status returning an error and no status available. This led to a python exception. This bug has been fixed and bindings are now more reliable when managing block jobs.

• Fixed a race condition leading to a crash when two threads were working over the same domain. This has been fixed.

• Previously, if not SCSI controller model, or no controller at all were specified, libvirt failed to find a suitable SCSI controller. This has been fixed: libvirt now checks virtio-scsi when searching for suitable model.

• Fixed a race condition between a thread starting a virtual machine with a guest agent configured and a thread that was killing the VM process (or the process crashing).

• Added a check for transient domain to prevent some applications to take an incorrect action when a guest had been migrated but before its removal.

• Changed the default for forwardPlainNames to "Yes".

• libvirt now only prevents the forwarding of DNS requests for unqualified names.

• sanlock daemon's limit of 48 characters on the lock owner name prevented domains with names longer than 48 characters from starting. This has been fixed, libvirt now truncates the domain name if needed when sending it to sanlock.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libvirt-0.10.2-29.5.0.1.AXS4.src.rpm
    MD5: 3c7fecd081e68937a046c3977118e813
    SHA-256: 99dca58f01d2e341dc6b386b0aa7e7bb0b470d5ec271dd479fd997509f4db222
    Size: 21.87 MB

Asianux Server 4 for x86
  1. libvirt-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 7f61b694fbcb486bf707d697e4434f08
    SHA-256: 3340811a2faee5d9ec6d3896242201ef0fbd4698b36a024e4a1b23785e0d4fe3
    Size: 2.11 MB
  2. libvirt-client-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 78e0cfe9716aa8bcd763908097466acf
    SHA-256: 655e1f711c4dee56a192b15bfe9463bbc85ce1de3d69cdab283b1c93e18b48f5
    Size: 4.02 MB
  3. libvirt-devel-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 1442934d8a63082e5af923a247c3e59b
    SHA-256: 0513bc5accd63569d013367766ecca3c8a757403d1fd7041275097137d029a23
    Size: 410.18 kB
  4. libvirt-python-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 3b690768793f1d7b287db03738a8137a
    SHA-256: dd5e40da470bb48dd8da77d2d2f038e20a8d7bcfbcc006b91446beda08589f17
    Size: 475.57 kB

Asianux Server 4 for x86_64
  1. libvirt-0.10.2-29.5.0.1.AXS4.x86_64.rpm
    MD5: 59ea3f16b3396930a88559c5445e66c1
    SHA-256: e36835d97c549ae1c52ff296d5ea9c028390a7bcdae0dd41939c3814e967545c
    Size: 2.36 MB
  2. libvirt-client-0.10.2-29.5.0.1.AXS4.x86_64.rpm
    MD5: 23b526685fdd6749c1ee70345e751236
    SHA-256: 90e0f2a5d0cb4ae925c6c8542ac8f43c9e2b42ba7d3ca14bffac52153d877a3e
    Size: 4.03 MB
  3. libvirt-devel-0.10.2-29.5.0.1.AXS4.x86_64.rpm
    MD5: 7d812b8c34fd8ebf0107d87bbce10178
    SHA-256: f4ccb96de08c0bbcf0bc043e7828fb0682fe948dc48a7ade87d6898a15d153a0
    Size: 409.80 kB
  4. libvirt-python-0.10.2-29.5.0.1.AXS4.x86_64.rpm
    MD5: 94777be7eb04f9846776ef8c51ea4ce6
    SHA-256: b827ac832d4ac24547f4ec4a22250aaa1850aadc5cf9135bdf5230181bd89f17
    Size: 475.63 kB
  5. libvirt-client-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 78e0cfe9716aa8bcd763908097466acf
    SHA-256: 655e1f711c4dee56a192b15bfe9463bbc85ce1de3d69cdab283b1c93e18b48f5
    Size: 4.02 MB
  6. libvirt-devel-0.10.2-29.5.0.1.AXS4.i686.rpm
    MD5: 1442934d8a63082e5af923a247c3e59b
    SHA-256: 0513bc5accd63569d013367766ecca3c8a757403d1fd7041275097137d029a23
    Size: 410.18 kB