USN-6253-1: libvirt vulnerability
26 July 2023
libvirt could be made to stop responding or crash if it received specially crafted commands.
Releases
Packages
- libvirt - Libvirt virtualization toolkit
Details
It wad discovered that libvirt incorrectly handled locking when processing
certain requests. A local attacker could possibly use this issue to cause
libvirt to stop responding or crash, resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
-
libvirt-daemon
-
9.0.0-2ubuntu1.2
-
libvirt-daemon-system
-
9.0.0-2ubuntu1.2
-
libvirt0
-
9.0.0-2ubuntu1.2
After a standard system update you need to reboot your computer to make all
the necessary changes.