Package "libvirt0"
| Name: |
libvirt0
|
Description: |
virtualization library
|
| Latest version: |
11.6.0-1ubuntu3.2 |
| Release: |
questing (25.10) |
| Level: |
updates |
| Repository: |
main |
| Head package: |
libvirt |
| Homepage: |
https://libvirt.org/ |
Links
Download "libvirt0"
Other versions of "libvirt0" in Questing
Changelog
|
libvirt (11.6.0-1ubuntu3.2) questing-security; urgency=medium
* SECURITY UPDATE: memory consumption DoS via XML parsing
- debian/patches/CVE-2025-12748-1.patch: add virDomainDefIDsParseString
in src/conf/domain_conf.c, src/conf/domain_conf.h,
src/libvirt_private.syms.
- debian/patches/CVE-2025-12748-2.patch: check ACLs before parsing the
whole domain XML in src/bhyve/bhyve_driver.c.
- debian/patches/CVE-2025-12748-3.patch: check ACLs before parsing the
whole domain XML in src/libxl/libxl_driver.c,
- debian/patches/CVE-2025-12748-4.patch: check ACLs before parsing the
whole domain XML in src/lxc/lxc_driver.c.
- debian/patches/CVE-2025-12748-5.patch: check ACLs before parsing the
whole domain XML in src/vz/vz_driver.c.
- debian/patches/CVE-2025-12748-6.patch: check ACLs before parsing the
whole domain XML in src/ch/ch_driver.c.
- debian/patches/CVE-2025-12748-7.patch: check ACLs before parsing the
whole domain XML in src/qemu/qemu_driver.c,
src/qemu/qemu_migration.c, src/qemu/qemu_migration.h,
src/qemu/qemu_saveimage.c, src/qemu/qemu_saveimage.h,
src/qemu/qemu_snapshot.c.
- debian/patches/CVE-2025-12748-8.patch: fix typo in bhyve driver in
src/bhyve/bhyve_driver.c.
- CVE-2025-12748
* SECURITY UPDATE: incorrect world-readable permissions on snapshots
- debian/patches/CVE-2025-13193.patch: set umask for qemu-img when
creating external inactive snapshots in src/qemu/qemu_snapshot.c.
- CVE-2025-13193
-- Marc Deslauriers <email address hidden> Mon, 08 Dec 2025 09:16:59 -0500
|
| Source diff to previous version |
| CVE-2025-12748 |
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL c |
| CVE-2025-13193 |
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivil |
|
|
libvirt (11.6.0-1ubuntu3.1) questing; urgency=medium
* d/p/u-aa/lp2127492-*: apparmor: Allow AMD-SEV device access for
AMD-SEV VM (LP: #2127492)
-- Hector Cao <email address hidden> Wed, 12 Nov 2025 12:40:51 +0100
|
| 2127492 |
permission denied for /dev/sev when run AMD-SEV ES VM |
|
About
-
Send Feedback to @ubuntu_updates