| libvirt-devel-4.5.0-36.el7_9.3.x86_64
              [344 KiB] | Changelog
              by Jiri Denemark (2020-10-20): - rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549) | 
            | libvirt-devel-4.5.0-36.el7_9.3.i686
              [344 KiB] | Changelog
              by Jiri Denemark (2020-10-20): - rpc: gendispatch: handle empty flags (CVE-2020-25637)
- rpc: add support for filtering @acls by uint params (CVE-2020-25637)
- rpc: require write acl for guest agent in virDomainInterfaceAddresses (CVE-2020-25637)
- qemu: agent: set ifname to NULL after freeing (CVE-2020-25637)
- conf: properly clear out autogenerated macvtap names when formatting/parsing (rhbz#1868549) | 
            | libvirt-devel-4.5.0-36.el7.x86_64
              [343 KiB] | Changelog
              by Jiri Denemark (2020-05-13): - virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976) | 
            | libvirt-devel-4.5.0-36.el7.i686
              [343 KiB] | Changelog
              by Jiri Denemark (2020-05-13): - virDevMapperGetTargetsImpl: Be tolerant to kernels without DM support (rhbz#1823976)
- virDevMapperGetTargetsImpl: quit early if device is not a devmapper target (rhbz#1823976) | 
            | libvirt-devel-4.5.0-23.el7.i686
              [338 KiB] | Changelog
              by Jiri Denemark (2019-06-20): - api: disallow virDomainSaveImageGetXMLDesc on read-only connections (CVE-2019-10161)
- api: disallow virDomainManagedSaveDefineXML on read-only connections (CVE-2019-10166)
- api: disallow virConnectGetDomainCapabilities on read-only connections (CVE-2019-10167)
- api: disallow virConnect*HypervisorCPU on read-only connections (CVE-2019-10168) | 
            | libvirt-devel-4.5.0-23.el7.x86_64
              [338 KiB] | Changelog
              by Jiri Denemark (2019-06-20): - api: disallow virDomainSaveImageGetXMLDesc on read-only connections (CVE-2019-10161)
- api: disallow virDomainManagedSaveDefineXML on read-only connections (CVE-2019-10166)
- api: disallow virConnectGetDomainCapabilities on read-only connections (CVE-2019-10167)
- api: disallow virConnect*HypervisorCPU on read-only connections (CVE-2019-10168) | 
            | libvirt-devel-4.5.0-10.el7_6.12.x86_64
              [327 KiB] | Changelog
              by Jiri Denemark (2019-06-18): - api: disallow virDomainSaveImageGetXMLDesc on read-only connections (CVE-2019-10161)
- api: disallow virDomainManagedSaveDefineXML on read-only connections (CVE-2019-10166)
- api: disallow virConnectGetDomainCapabilities on read-only connections (CVE-2019-10167)
- api: disallow virConnect*HypervisorCPU on read-only connections (CVE-2019-10168) | 
            | libvirt-devel-4.5.0-10.el7_6.12.i686
              [327 KiB] | Changelog
              by Jiri Denemark (2019-06-18): - api: disallow virDomainSaveImageGetXMLDesc on read-only connections (CVE-2019-10161)
- api: disallow virDomainManagedSaveDefineXML on read-only connections (CVE-2019-10166)
- api: disallow virConnectGetDomainCapabilities on read-only connections (CVE-2019-10167)
- api: disallow virConnect*HypervisorCPU on read-only connections (CVE-2019-10168) | 
            | libvirt-devel-4.5.0-10.el7_6.10.i686
              [326 KiB] | Changelog
              by Jiri Denemark (2019-05-16): - virnwfilterbindingobj: Introduce and use virNWFilterBindingObjStealDef (rhbz#1702173)
- admin: reject clients unless their UID matches the current UID (CVE-2019-10132)
- locking: restrict sockets to mode 0600 (CVE-2019-10132)
- logging: restrict sockets to mode 0600 (CVE-2019-10132) | 
            | libvirt-devel-4.5.0-10.el7_6.10.x86_64
              [344 KiB] | Changelog
              by Jiri Denemark (2019-05-16): - virnwfilterbindingobj: Introduce and use virNWFilterBindingObjStealDef (rhbz#1702173)
- admin: reject clients unless their UID matches the current UID (CVE-2019-10132)
- locking: restrict sockets to mode 0600 (CVE-2019-10132)
- logging: restrict sockets to mode 0600 (CVE-2019-10132) | 
            | libvirt-devel-4.5.0-10.el7_6.9.x86_64
              [343 KiB] | Changelog
              by Jiri Denemark (2019-04-16): - qemu: Don't cache microcode version (CVE-2018-12127, CVE-2018-12126, CVE-2018-12130) | 
            | libvirt-devel-4.5.0-10.el7_6.9.i686
              [343 KiB] | Changelog
              by Jiri Denemark (2019-04-16): - qemu: Don't cache microcode version (CVE-2018-12127, CVE-2018-12126, CVE-2018-12130) |