-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2019-5f105dd2b6 2019-05-25 01:04:18.279569 --------------------------------------------------------------------------------
Name : libvirt Product : Fedora 30 Version : 5.1.0 Release : 6.fc30 URL : https://libvirt.org/ Summary : Library providing a simple virtualization API Description : Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.
-------------------------------------------------------------------------------- Update Information:
Fix systemd socket permissions (CVE-2019-10132) The virtlockd-admin.socket, virtlogd-admin.sock, virtlockd.socket & virtlogd.socket units must be restarted, if currently running. This can be done with a host reboot or systemctl commands. -------------------------------------------------------------------------------- ChangeLog:
* Tue May 21 2019 Daniel P. Berrang�� berrange@redhat.com - 5.1.0-6 - Fix systemd socket permissions - Resolves: rhbz #1712498 (CVE-2019-10132) * Tue May 14 2019 Daniel P. Berrang�� berrange@redhat.com - 5.1.0-5 - Define md-clear CPUID bit - Resolves: rhbz #1709977 (CVE-2018-12126), rhbz #1709979 (CVE-2018-12127), rhbz #1709997 (CVE-2018-12130), rhbz #1709984 (CVE-2019-11091) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1706067 - CVE-2019-10132 libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter https://bugzilla.redhat.com/show_bug.cgi?id=1706067 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5f105dd2b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------