UbuntuUpdates.org

Package "libvirt-daemon"

Name: libvirt-daemon

Description:

Virtualization daemon

Latest version: 10.0.0-2ubuntu8.19
Release: noble (24.04)
Level: updates
Repository: main
Head package: libvirt
Homepage: https://libvirt.org/

Links


Download "libvirt-daemon"


Other versions of "libvirt-daemon" in Noble

Repository Area Version
base main 10.0.0-2ubuntu8
security main 10.0.0-2ubuntu8.19

Changelog

Version: 10.0.0-2ubuntu8.19 2026-09-28 15:07:19 UTC

libvirt (10.0.0-2ubuntu8.19) noble-security; urgency=medium

  [ Hector Cao ]
  * rpc: avoid leak of GSource in use for interrupting main loop
    d/p/u/lp2142757-rpc-avoid-leak-of-GSource-in-use.patch
    (LP: #2142757)

  [ Marc Deslauriers ]
  * SECURITY UPDATE: integer overflow in NodeGetFreePages RPC handler
    - debian/patches/CVE-2026-18917.patch: remote: Fix integer overflow in RPC
      handler for virNodeGetFreePages in src/remote/remote_daemon_dispatch.c.
    - CVE-2026-18917
  * SECURITY UPDATE: symlink-following flaw
    - debian/patches/CVE-2026-77159.patch: qemu: tpm: Avoid following symlinks
      when chown'ing log file in src/qemu/qemu_tpm.c.
    - CVE-2026-77159

 -- Marc Deslauriers Fri, 25 Sep 2026 09:30:32 -0400

Source diff to previous version
2142757 libvirt 10.0.0-2ubuntu8.x - rpc: leak of GSource in use for interrupting main loop
CVE-2026-18917 A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla
CVE-2026-77159 A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi

Version: 10.0.0-2ubuntu8.17 2026-09-23 18:07:33 UTC

libvirt (10.0.0-2ubuntu8.17) noble; urgency=medium

  * d/p/u-aa/apparmor-Allow-vfio-ccw-hostdev-sysfs-access.patch:
    Allow vfio-ccw hostdev sysfs access (LP: #2056441)

 -- Hector Cao Wed, 26 Aug 2026 15:21:41 +0200

Source diff to previous version

Version: 10.0.0-2ubuntu8.16 2026-08-19 20:08:11 UTC
No changelog available yet.
Source diff to previous version

Version: 10.0.0-2ubuntu8.15 2026-07-22 20:08:06 UTC
No changelog available yet.
Source diff to previous version

Version: 10.0.0-2ubuntu8.14 2026-06-18 16:07:44 UTC

  libvirt (10.0.0-2ubuntu8.14) noble; urgency=medium

  * Fix excessive memory allocation when physical_package_id is large
    (LP: #2153530).
    - d/p/ubuntu/lp2153530-fix-max-socket-calculation.patch: compute socket
      count from unique package IDs instead of the maximum value.

 -- Seyeong Kim <email address hidden> Thu, 21 May 2026 03:45:44 +0000

2153530 libvirt: excessive memory allocation / OOM when physical_package_id is large



About   -   Send Feedback to @ubuntu_updates