USN-6763-1: libvirt vulnerability
7 May 2024
libvirt could allow unintended access to the virtproxyd service.
Releases
Packages
- libvirt - Libvirt virtualization toolkit
Details
Martin Širokov discovered that libvirt incorrectly handled certain memory
operations. A local attacker could possibly use this issue to access
virtproxyd without authorization.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
-
libvirt-daemon
-
10.0.0-2ubuntu8.2
-
libvirt-daemon-system
-
10.0.0-2ubuntu8.2
-
libvirt0
-
10.0.0-2ubuntu8.2
After a standard system update you need to reboot your computer to make all
the necessary changes.