-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 12 Jun 2019 10:13:38 +0200 Source: libvirt Binary: libvirt-clients libvirt-daemon libvirt-daemon-system libvirt0 libvirt-doc libvirt-dev libvirt-sanlock libnss-libvirt Architecture: amd64 Version: 3.0.0-4+deb9u4 Distribution: stretch-security Urgency: medium Maintainer: amd64 Build Daemon (x86-grnet-01) Changed-By: Guido Günther Description: libnss-libvirt - nss plugin providing IP add ress resolution for virtual machines libvirt-clients - Programs for the libvirt library libvirt-daemon - Virtualization daemon libvirt-daemon-system - Libvirt daemon configuration files libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt-sanlock - Sanlock plugin for virtlockd libvirt0 - library for interfacing with different virtualization systems Changes: libvirt (3.0.0-4+deb9u4) stretch-security; urgency=medium . * Fix CVEs related to privilege escalations on R/O connections. - CVE-2019-10161: CVE-2019-10161-api-disallow-virDomainSaveImageGetXMLDesc-.patch - CVE-2019-10167: api-disallow-virConnectGetDomainCapabilities-on-read-only.patch * cpu_map: Define md-clear CPUID bit. CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091 * Add spec-ctrl and ibpb CPU features and ibrs CPU models. CVE-2017-5753, CVE-2017-5715 * Add ssbd CPU feature. CVE-2018-3639 Checksums-Sha1: 894d85310ae6b39246ab023204c4a01206976add 355772 libnss-libvirt-dbgsym_3.0.0-4+deb9u4_amd64.deb 4787e7f3f9b2df641064779c948e1c0de9878a65 162034 libnss-libvirt_3.0.0-4+deb9u4_amd64.deb f2484053e8d5d3797db21d36ab70b21b3620612e 1658332 libvirt-clients-dbgsym_3.0.0-4+deb9u4_amd64.deb 12cae3b8e3002af9a9966665ab8ddabc20a04b0e 622562 libvirt-clients_3.0.0-4+deb9u4_amd64.deb e07aefa68da03983879dd9b254a776eabd6efb39 10796592 libvirt-daemon-dbgsym_3.0.0-4+deb9u4_amd64.deb 2bacfd2f9064dad6691f6ac295ba960317173083 342582 libvirt-daemon-system-dbgsym_3.0.0-4+deb9u4_amd64.deb 0bed26e8f5c834fda98b8a92fa1c0df250f5fb9d 178750 libvirt-daemon-system_3.0.0-4+deb9u4_amd64.deb 16cad602a5887e6b575283ba71c8aed960f76ce7 2143608 libvirt-daemon_3.0.0-4+deb9u4_amd64.deb 645d41002c21a033829cf01d660edadd319267fb 175738 libvirt-dev_3.0.0-4+deb9u4_amd64.deb 6d37c2eb4cab53ba7ecb722295e95619bfd8e4b8 105542 libvirt-sanlock-dbgsym_3.0.0-4+deb9u4_amd64.deb f9d08892a7f7f12e987072f832efd4cea9dbc237 79694 libvirt-sanlock_3.0.0-4+deb9u4_amd64.deb e3b90dea5ea22071632b3647eda7ed1c05399ceb 4133124 libvirt0-dbgsym_3.0.0-4+deb9u4_amd64.deb 06be6f69c94daf98b02e51e7658e82226d47e209 4026932 libvirt0_3.0.0-4+deb9u4_amd64.deb a6b840c66323f68f06068ed66432023546f04bd4 15935 libvirt_3.0.0-4+deb9u4_amd64.buildinfo Checksums-Sha256: aebff24104a453f0b60eb15f1dab5076a10e421d5ff198041e5089244315d435 355772 libnss-libvirt-dbgsym_3.0.0-4+deb9u4_amd64.deb 5aefa9fea868d0984d7ab9495676702109496174e4308e6abf10a3b417a0bd57 162034 libnss-libvirt_3.0.0-4+deb9u4_amd64.deb a04f294f3e3909e0cd9ae46e10c069862049e4b18a90102bc60c4b0d786701d2 1658332 libvirt-clients-dbgsym_3.0.0-4+deb9u4_amd64.deb 802a452c7fba45ceb820d3c1ca081896dd5bf0481fbdc9f542ed298e7bf60df7 622562 libvirt-clients_3.0.0-4+deb9u4_amd64.deb c0541ee4db7f95dd0468434e153ac72e4149f96a54a0c8dd7aeea698a5aa931f 10796592 libvirt-daemon-dbgsym_3.0.0-4+deb9u4_amd64.deb eee91b94318a4fd5277c7b9c2eb4acaf33bc30ef7e3d083b3d9f83157514802a 342582 libvirt-daemon-system-dbgsym_3.0.0-4+deb9u4_amd64.deb e9e0e081374de1393e70bd57a6916c7fac4f1386456273ad52f7809f047babdc 178750 libvirt-daemon-system_3.0.0-4+deb9u4_amd64.deb 6b9d8792f3778ef60423ab673a5892fc60e1fd500773564c06986f9b87127db1 2143608 libvirt-daemon_3.0.0-4+deb9u4_amd64.deb 0db08b6e566f7f5d434309bb0053d0d44d4ba8ab5b62c3b54c51edac299e23b0 175738 libvirt-dev_3.0.0-4+deb9u4_amd64.deb 70469564efc78ffdceb87ceb36c453edd27e4e0f1b9c5ff1cdf1671062aaa0dc 105542 libvirt-sanlock-dbgsym_3.0.0-4+deb9u4_amd64.deb 0ca93ee0abd251b42e410bf07f018e6fe48d3fb49e8cecde292995dc0728c5ea 79694 libvirt-sanlock_3.0.0-4+deb9u4_amd64.deb 8f5469940971fe4eab7c50e56c3fe619e7396e54533b8c0532857a949a634899 4133124 libvirt0-dbgsym_3.0.0-4+deb9u4_amd64.deb 922831f2732e370c427bb6313ac0e061dfb508c0302b5f91dd24ca220bb36abe 4026932 libvirt0_3.0.0-4+deb9u4_amd64.deb cfdc3dd7519e251e3c18d7ac70e224f43cc77ba82e0e2bc6debad68c07932e0b 15935 libvirt_3.0.0-4+deb9u4_amd64.buildinfo Files: a75290ea901917ba31907805cec724e6 355772 debug extra libnss-libvirt-dbgsym_3.0.0-4+deb9u4_amd64.deb cbf709f5c6809859fa8966db1b484a87 162034 libs extra libnss-libvirt_3.0.0-4+deb9u4_amd64.deb f144656e0310fa334641c800cd2a3d93 1658332 debug extra libvirt-clients-dbgsym_3.0.0-4+deb9u4_amd64.deb a1ff31bfd816fc0957d27446b0bd8660 622562 admin optional libvirt-clients_3.0.0-4+deb9u4_amd64.deb d95881e7a463b5f33f7ade76a495f0da 10796592 debug extra libvirt-daemon-dbgsym_3.0.0-4+deb9u4_amd64.deb 1574813d941000f9955d796a07de0a5f 342582 debug extra libvirt-daemon-system-dbgsym_3.0.0-4+deb9u4_amd64.deb 45e52b941c82bb0d685d1453b143e2ec 178750 admin optional libvirt-daemon-system_3.0.0-4+deb9u4_amd64.deb b64a0cac452202b40e82892d9594e1e0 2143608 admin optional libvirt-daemon_3.0.0-4+deb9u4_amd64.deb 5007f32a4d1d342a99d6e351c0bcb808 175738 libdevel optional libvirt-dev_3.0.0-4+deb9u4_amd64.deb be7dd768e331faf24d53acb5999d2fda 105542 debug extra libvirt-sanlock-dbgsym_3.0.0-4+deb9u4_amd64.deb 01b389aeafcaa0a95fc19b5b2aacaad6 79694 libs extra libvirt-sanlock_3.0.0-4+deb9u4_amd64.deb a7e076f16b1d2d97d5910e1e65d615eb 4133124 debug extra libvirt0-dbgsym_3.0.0-4+deb9u4_amd64.deb 73842cf1e3ae6c2b736fd585f4059f4d 4026932 libs optional libvirt0_3.0.0-4+deb9u4_amd64.deb 26664313e04130050af3d7806d278205 15935 libs optional libvirt_3.0.0-4+deb9u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE56RkdImmGnu/qTMEtnmMmMOJfQ0FAl0MG0sACgkQtnmMmMOJ fQ1zsQ/5Aa18EyHtOzS9od/SvviXy1WZ70FXvDje4EGU/ggNW/p2Te4PuZhlNJQz 4/qaq0qnvpKnZ+Vh1t3nCih1uIm5XCmu1Crav4LvM27UlKxcjPhOmSCJcZOe1wUc sd7VLL+vVODDjV5C0QZEOFgTzHSwIq963UzOYQBcUgK/dZ59e8Jd+o1l6sqMFx0T mb6K/c1eBdAxHC3PcmM66V+fXVcbKiB6U4i7tZFRsWhjpinSDBJjTkdO4Sy8xdPf vwq3HmDlZyY3db+RZSdSh8WrCYJMtYZuW9148OB/q6mpBl7gV0By9cCMKDd1ud8z Xy5AlEMpPNkInWJjQgGy3D1Quzl2sCNN/jZbgB4CfAqswwUsde6u1xgxTkMH6scK ZONI7Soc9TyGQ9ymkzWJUvNVnJYpWdnKWbQNMHXB0eI5pbJD3fiS20Dk0KxcScgK Fff6Wwf+Wf3Plfieopa2WI74cafA9HQLipf+cSE8To0+7FCU9GkbGCAAH/ElyLjW GsZNDY+sFKpt0cGSBSp1AVafpL6EMrPItsSFAGmuevbStydfmR3iyIpNkj9nsxhm lBoRubwM/JfLLQanfFuoci21fp3ZeOmBEKlCell4vCrPE2N8QIlJmhQvZhnHrvn5 ut8ul2QfXZtQe6go3zjiaYU7lnSzKDgPmcWw4i+YfHXrbqGTpsw= =P8u6 -----END PGP SIGNATURE-----