meta-virtualization/recipes-extended
Xu, Yanfei da0f1599ce libvirt: fix CVE-2021-3667
Backport a fix for CVE-2021-3667.

The CVE discription: An improper locking issue was found in the
virStoragePoolLookupByTargetPath API of libvirt. It occurs in the
storagePoolLookupByTargetPath function where a locked virStoragePoolObj
object is not properly released on ACL permission failure. Clients
connecting to the read-write socket with limited ACL permissions could
use this flaw to acquire the lock and prevent other users from accessing
storage pool/volume APIs, resulting in a denial of service condition.
The highest threat from this vulnerability is to system availability.

Refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1986094

Signed-off-by: Yanfei Xu <yanfei.xu@windriver.com>
Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
2021-11-24 16:57:20 -05:00
..
ceph ceph: 15.2.12 -> 15.2.15 2021-10-28 15:30:19 -04:00
cloud-init global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
dev86 global: add explicit branch to all SRC_URIs 2021-11-02 09:57:03 -04:00
diod global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
fuse-overlayfs global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
hyperstart global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
images xtf: add testimage integration to run XTF test cases in OEQA 2021-09-02 16:36:23 -04:00
iptables global: overrides syntax conversion 2021-08-02 17:17:53 -04:00
ipxe global: add explicit branch to all SRC_URIs 2021-11-02 09:57:03 -04:00
irqbalance irqbalance: bump SRCREV to latest 2021-11-08 09:18:20 -05:00
kvmtool global: add explicit branch to all SRC_URIs 2021-11-02 09:57:03 -04:00
libibverbs Revert "ceph/libibverbs: replace libibverbs with rdma-core" 2021-09-17 08:27:13 -04:00
libvirt libvirt: fix CVE-2021-3667 2021-11-24 16:57:20 -05:00
libvmi global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
nagios global: overrides syntax conversion 2021-08-02 17:17:53 -04:00
oath oath: inherit pkgconfig 2021-09-30 22:37:10 -04:00
seabios global: overrides syntax conversion 2021-08-02 17:17:53 -04:00
upx global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00
uxen uxen: update guest tools to 4.1.8 2021-08-27 10:50:45 -04:00
vgabios global: overrides syntax conversion 2021-08-02 17:17:53 -04:00
xen global: add explicit branch to all SRC_URIs 2021-11-02 09:57:03 -04:00
xvisor global: convert github SRC_URIs to use https protocol 2021-11-02 09:57:03 -04:00