libvirt-0.10.2-62.1.0.1.AXS4

エラータID: AXSA:2018-2507:01

Release date: 
Tuesday, January 9, 2018 - 14:12
Subject: 
libvirt-0.10.2-62.1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.

Security Fix(es):

* An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the way the speculative execution can be exploited. Variant CVE-2017-5715 triggers the speculative execution by utilizing branch target injection. It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory accesses may cause allocation into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to cross the syscall and guest/host boundaries and read privileged memory by conducting targeted cache side-channel attacks. (CVE-2017-5715)

Note: This is the libvirt side of the CVE-2017-5715 mitigation.

Asianux would like to thank Google Project Zero for reporting this issue.

CVE-2017-5715
Systems with microprocessors utilizing speculative execution and
indirect branch prediction may allow unauthorized disclosure of
information to an attacker with local user access via a side-channel
analysis.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libvirt-0.10.2-62.1.0.1.AXS4.src.rpm
    MD5: fc8e210e3a37a6d9a9351037ab50e38c
    SHA-256: f81bc5cdf0e23645dc68be02805f9d69a11357673a34f4563d64958a457cbfde
    Size: 22.42 MB

Asianux Server 4 for x86
  1. libvirt-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: 07a0a895324b7499245afaee1363336d
    SHA-256: 24d438bafc73e02da32d2733a7a7ebced2c9c34bfbb180a8a09b8d3f7b903d86
    Size: 2.15 MB
  2. libvirt-client-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: 647e0c30d24e57342851a973c9c93d87
    SHA-256: 7208cc7b5192a86fe7ea732d55b609f32f74135fb283df1d403aff351786fadc
    Size: 4.06 MB
  3. libvirt-devel-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: 4b9e099ce7f48d358c077d0a93123683
    SHA-256: d7005654ebc5c940a28cee79b283404bece95a3b01d860395499acd769357f58
    Size: 440.32 kB
  4. libvirt-python-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: df87a5deb27db98a8fe6c522e3992d9a
    SHA-256: f711dc05c10ae20057ecebb6b7c3c9cc2e5f44a2fb7a3eb933005d4afe580f24
    Size: 504.89 kB

Asianux Server 4 for x86_64
  1. libvirt-0.10.2-62.1.0.1.AXS4.x86_64.rpm
    MD5: 39849ef0189ce1072586d5107f97e675
    SHA-256: ffffcd063f13ef49bdb994493bd62196f0a54be20af6869b9c67f0dacab7763e
    Size: 2.43 MB
  2. libvirt-client-0.10.2-62.1.0.1.AXS4.x86_64.rpm
    MD5: d33d173253009a190bd542b6efda7de4
    SHA-256: 7a1a4a3f180e0afcd538a77bf5cc38773b673e206884a78b054440a931629681
    Size: 4.08 MB
  3. libvirt-devel-0.10.2-62.1.0.1.AXS4.x86_64.rpm
    MD5: 56cb19d8f688beab7decf5012f1423ab
    SHA-256: bef1c1d422a46339412e09c82a185cded3dea79230bbf0e6d24306c3de2c8a67
    Size: 439.89 kB
  4. libvirt-python-0.10.2-62.1.0.1.AXS4.x86_64.rpm
    MD5: 495714f74b8f12360673827b8b3579dd
    SHA-256: c2ca1a3e63ad416714a2ce8745a84ba0d980e434e3748b87dcb8705a92679ade
    Size: 504.47 kB
  5. libvirt-client-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: 647e0c30d24e57342851a973c9c93d87
    SHA-256: 7208cc7b5192a86fe7ea732d55b609f32f74135fb283df1d403aff351786fadc
    Size: 4.06 MB
  6. libvirt-devel-0.10.2-62.1.0.1.AXS4.i686.rpm
    MD5: 4b9e099ce7f48d358c077d0a93123683
    SHA-256: d7005654ebc5c940a28cee79b283404bece95a3b01d860395499acd769357f58
    Size: 440.32 kB