This bug was fixed in the package libvirt - 10.0.0-2ubuntu8.19

---------------
libvirt (10.0.0-2ubuntu8.19) noble-security; urgency=medium

  [ Hector Cao ]
  * rpc: avoid leak of GSource in use for interrupting main loop
    d/p/u/lp2142757-rpc-avoid-leak-of-GSource-in-use.patch
    (LP: #2142757)

  [ Marc Deslauriers ]
  * SECURITY UPDATE: integer overflow in NodeGetFreePages RPC handler
    - debian/patches/CVE-2026-18917.patch: remote: Fix integer overflow in RPC
      handler for virNodeGetFreePages in src/remote/remote_daemon_dispatch.c.
    - CVE-2026-18917
  * SECURITY UPDATE: symlink-following flaw
    - debian/patches/CVE-2026-77159.patch: qemu: tpm: Avoid following symlinks
      when chown'ing log file in src/qemu/qemu_tpm.c.
    - CVE-2026-77159

 -- Marc Deslauriers <[email protected]>  Fri, 25 Sep 2026
09:30:32 -0400

** Changed in: libvirt (Ubuntu Noble)
       Status: In Progress => Fix Released

** CVE added: https://cve.org/CVERecord?id=CVE-2026-18917

** CVE added: https://cve.org/CVERecord?id=CVE-2026-77159

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2142757

Title:
  libvirt 10.0.0-2ubuntu8.x - rpc: leak of GSource in use for
  interrupting main loop

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2142757/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to