This bug was fixed in the package libvirt - 12.6.0-1ubuntu4
---------------
libvirt (12.6.0-1ubuntu4) stonking; urgency=medium
* d/p/u-aa/lp2167823-apparmor-allow-reading-uevent-for-usb-hostdev.patch:
Allow QEMU to read the parent USB host controller's uevent so that
USB <hostdev> attach/hotplug is not denied by AppArmor (LP: #2167823)
libvirt (12.6.0-1ubuntu3) stonking; urgency=medium
* SECURITY UPDATE: integer overflow in NodeGetFreePages RPC handler
- debian/patches/CVE-2026-18917.patch: remote: Fix integer overflow in RPC
handler for virNodeGetFreePages in src/remote/remote_daemon_dispatch.c.
- CVE-2026-18917
* SECURITY UPDATE: symlink-following flaw
- debian/patches/CVE-2026-77159.patch: qemu: tpm: Avoid following symlinks
when chown'ing log file in src/qemu/qemu_tpm.c.
- CVE-2026-77159
-- Hector Cao <[email protected]> Tue, 29 Sep 2026 01:12:05
+0200
** Changed in: libvirt (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-18917
** CVE added: https://cve.org/CVERecord?id=CVE-2026-77159
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167823
Title:
AppArmor denies QEMU to read
/sys/devices/pci0000:00/0000:00:01.2/uevent
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/2167823/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs