UbuntuUpdates.org

Package "libvirt-hwe"

Name: libvirt-hwe

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • virtualization library - clients
  • virtualization library - common files
  • virtualization daemon - common files
  • virtualization daemon - configuration files (default network)

Latest version: 12.0.0-1ubuntu5.5
Release: resolute (26.04)
Level: updates
Repository: main

Links



Other versions of "libvirt-hwe" in Resolute

Repository Area Version
base universe 12.0.0-1ubuntu5
security main 12.0.0-1ubuntu5.5
security universe 12.0.0-1ubuntu5.5
updates universe 12.0.0-1ubuntu5.5
proposed universe 12.0.0-1ubuntu5.3
proposed main 12.0.0-1ubuntu5.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 12.0.0-1ubuntu5.5 2026-09-28 15:07:22 UTC

libvirt-hwe (12.0.0-1ubuntu5.5) resolute-security; urgency=medium

  * SECURITY UPDATE: Privileged arbitrary command execution in network driver.
    - debian/patches/CVE-2026-61477-1.patch: Reject line breaks in DNS TXT
      record values in src/conf/network_conf.c
    - debian/patches/CVE-2026-61477-2.patch: Reject line breaks in DNS SRV
      domain and target in src/conf/network_conf.c
    - debian/patches/CVE-2026-61477-3.patch: Reject line breaks before
      writing dnsmasq DNS config in src/network/bridge_driver.c
    - debian/patches/CVE-2026-61477-4.patch: Add negative tests that feed
      XML numeric character references into the DNS TXT value and SRV
      domain/target attributes.
    - CVE-2026-61477
  * SECURITY UPDATE: Denial of service in XML parsing
    - debian/patches/CVE-2026-61478.patch: Fix crash searching for XML context
      string on errors in src/util/virxml.c
    - CVE-2026-61478
  * SECURITY UPDATE: Privilege escalation in Virtual TPM
    - debian/patches/CVE-2026-63622.patch: Do not follow symlinks in
      src/util/virfile.c
    - CVE-2026-63622
  * SECURITY UPDATE: Information disclosure in image cloning/conversion
    - debian/patches/CVE-2026-63623.patch: Create images with a private umask
      during qemu-img create/convert in src/storage/storage_util.c
    - CVE-2026-63623
  * SECURITY UPDATE: integer overflow in NodeGetFreePages RPC handler
    - debian/patches/CVE-2026-18917.patch: remote: Fix integer overflow in RPC
      handler for virNodeGetFreePages in src/remote/remote_daemon_dispatch.c.
    - CVE-2026-18917
  * SECURITY UPDATE: symlink-following flaw
    - debian/patches/CVE-2026-77159.patch: qemu: tpm: Avoid following symlinks
      when chown'ing log file in src/qemu/qemu_tpm.c.
    - CVE-2026-77159

 -- Marc Deslauriers Wed, 23 Sep 2026 14:46:22 -0400

Source diff to previous version
CVE-2026-61477 An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT recor
CVE-2026-63622 A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera
CVE-2026-63623 A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was
CVE-2026-18917 A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla
CVE-2026-77159 A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile wi

Version: 12.0.0-1ubuntu5.3 2026-09-23 18:07:37 UTC

libvirt-hwe (12.0.0-1ubuntu5.3) resolute; urgency=medium

  * d/p/u-aa/apparmor-Allow-vfio-ccw-hostdev-sysfs-access.patch:
    Allow vfio-ccw hostdev sysfs access (LP: #2056441)

 -- Hector Cao Wed, 19 Aug 2026 11:23:52 +0200

Source diff to previous version

Version: 12.0.0-1ubuntu5.2 2026-07-22 20:08:18 UTC
No changelog available yet.
Source diff to previous version

Version: 12.0.0-1ubuntu5.1 2026-06-18 16:07:52 UTC

  libvirt-hwe (12.0.0-1ubuntu5.1) resolute; urgency=medium

  * Fix excessive memory allocation when physical_package_id is large
    (LP: #2153530).
    - d/p/ubuntu/lp2153530-fix-max-socket-calculation.patch: compute socket
      count from unique package IDs instead of the maximum value.

 -- Hector Cao <email address hidden> Thu, 21 May 2026 15:49:24 +0200

2153530 libvirt: excessive memory allocation / OOM when physical_package_id is large



About   -   Send Feedback to @ubuntu_updates