File _patchinfo of Package patchinfo.32869
<patchinfo incident="32869">
<issue tracker="bnc" id="1220512">VM log files flooded with taint messages</issue>
<issue tracker="bnc" id="1221468">VUL-0: CVE-2024-2496: libvirt: NULL pointer dereference in udevConnectListAllInterfaces()</issue>
<issue tracker="bnc" id="1216980">Can not create a VM with virt-install using UEFI with "secure boot disabled"</issue>
<issue tracker="bnc" id="1214223">[XEN][MODULAR LIBVIRT] error: Failed to attach NAT virtual network interface to guest system</issue>
<issue tracker="bnc" id="1221237">VUL-0: CVE-2024-1441: libvirt: off-by-one error in udevListInterfacesByStatus()</issue>
<issue tracker="bnc" id="1221815">VUL-0: CVE-2024-2494: libvirt: negative g_new0 length can lead to unbounded memory allocation</issue>
<issue tracker="cve" id="2024-2494"/>
<issue tracker="cve" id="2024-1441"/>
<issue tracker="cve" id="2024-2496"/>
<packager>jfehlig</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for libvirt</summary>
<description>This update for libvirt fixes the following issues:
- CVE-2024-2494: Add a check for negative array lengths before allocation to prevent potential DoS. (bsc#1221815)
- CVE-2024-2496: Fixed NULL pointer dereference in udevConnectListAllInterfaces() (bsc#1221468).
- CVE-2024-1441: Fix off-by-one error in udevListInterfacesByStatus (bsc#1221237)
- qemu: domain: Fix logic when tainting domain (bsc#1220512)
- conf: Remove some firmware validation checks (bsc#1216980)
- libxl: Fix connection to modular network daemon (bsc#1214223)
</description>
</patchinfo>