SUSE-SU-2024:1099-1
Dashboard / Vulnerabilities / SUSE-SU-2024:1099-1
SUSE-SU-2024:1099-1
Summary: Security update for libvirt
Details: This update for libvirt fixes the following issues: - CVE-2024-2494: Add a check for negative array lengths before allocation to prevent potential DoS. (bsc#1221815) - CVE-2024-2496: Fixed NULL pointer dereference in udevConnectListAllInterfaces() (bsc#1221468). - CVE-2024-1441: Fix off-by-one error in udevListInterfacesByStatus (bsc#1221237) - qemu: domain: Fix logic when tainting domain (bsc#1220512) - conf: Remove some firmware validation checks (bsc#1216980) - libxl: Fix connection to modular network daemon (bsc#1214223)
References: https://www.suse.com/support/update/announcement/2024/suse-su-20241099-1/, https://bugzilla.suse.com/1214223, https://bugzilla.suse.com/1216980, https://bugzilla.suse.com/1220512, https://bugzilla.suse.com/1221237, https://bugzilla.suse.com/1221468, https://bugzilla.suse.com/1221815, https://www.suse.com/security/cve/CVE-2024-1441, https://www.suse.com/security/cve/CVE-2024-2494, https://www.suse.com/security/cve/CVE-2024-2496
Affected packages
Package
Name: libvirt
Purl: pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Affected ranges
Type: ECOSYSTEM
Events:
