{"affected":[{"ecosystem_specific":{"binaries":[{"libvirt":"4.0.0-8.23.1","libvirt-admin":"4.0.0-8.23.1","libvirt-client":"4.0.0-8.23.1","libvirt-daemon":"4.0.0-8.23.1","libvirt-daemon-config-network":"4.0.0-8.23.1","libvirt-daemon-config-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-interface":"4.0.0-8.23.1","libvirt-daemon-driver-libxl":"4.0.0-8.23.1","libvirt-daemon-driver-lxc":"4.0.0-8.23.1","libvirt-daemon-driver-network":"4.0.0-8.23.1","libvirt-daemon-driver-nodedev":"4.0.0-8.23.1","libvirt-daemon-driver-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-qemu":"4.0.0-8.23.1","libvirt-daemon-driver-secret":"4.0.0-8.23.1","libvirt-daemon-driver-storage":"4.0.0-8.23.1","libvirt-daemon-driver-storage-core":"4.0.0-8.23.1","libvirt-daemon-driver-storage-disk":"4.0.0-8.23.1","libvirt-daemon-driver-storage-iscsi":"4.0.0-8.23.1","libvirt-daemon-driver-storage-logical":"4.0.0-8.23.1","libvirt-daemon-driver-storage-mpath":"4.0.0-8.23.1","libvirt-daemon-driver-storage-rbd":"4.0.0-8.23.1","libvirt-daemon-driver-storage-scsi":"4.0.0-8.23.1","libvirt-daemon-hooks":"4.0.0-8.23.1","libvirt-daemon-lxc":"4.0.0-8.23.1","libvirt-daemon-qemu":"4.0.0-8.23.1","libvirt-daemon-xen":"4.0.0-8.23.1","libvirt-doc":"4.0.0-8.23.1","libvirt-libs":"4.0.0-8.23.1","libvirt-lock-sanlock":"4.0.0-8.23.1","libvirt-nss":"4.0.0-8.23.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 9","name":"libvirt","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.0-8.23.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libvirt":"4.0.0-8.23.1","libvirt-admin":"4.0.0-8.23.1","libvirt-client":"4.0.0-8.23.1","libvirt-daemon":"4.0.0-8.23.1","libvirt-daemon-config-network":"4.0.0-8.23.1","libvirt-daemon-config-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-interface":"4.0.0-8.23.1","libvirt-daemon-driver-libxl":"4.0.0-8.23.1","libvirt-daemon-driver-lxc":"4.0.0-8.23.1","libvirt-daemon-driver-network":"4.0.0-8.23.1","libvirt-daemon-driver-nodedev":"4.0.0-8.23.1","libvirt-daemon-driver-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-qemu":"4.0.0-8.23.1","libvirt-daemon-driver-secret":"4.0.0-8.23.1","libvirt-daemon-driver-storage":"4.0.0-8.23.1","libvirt-daemon-driver-storage-core":"4.0.0-8.23.1","libvirt-daemon-driver-storage-disk":"4.0.0-8.23.1","libvirt-daemon-driver-storage-iscsi":"4.0.0-8.23.1","libvirt-daemon-driver-storage-logical":"4.0.0-8.23.1","libvirt-daemon-driver-storage-mpath":"4.0.0-8.23.1","libvirt-daemon-driver-storage-rbd":"4.0.0-8.23.1","libvirt-daemon-driver-storage-scsi":"4.0.0-8.23.1","libvirt-daemon-hooks":"4.0.0-8.23.1","libvirt-daemon-lxc":"4.0.0-8.23.1","libvirt-daemon-qemu":"4.0.0-8.23.1","libvirt-daemon-xen":"4.0.0-8.23.1","libvirt-doc":"4.0.0-8.23.1","libvirt-libs":"4.0.0-8.23.1","libvirt-lock-sanlock":"4.0.0-8.23.1","libvirt-nss":"4.0.0-8.23.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud Crowbar 9","name":"libvirt","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.0-8.23.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libvirt":"4.0.0-8.23.1","libvirt-admin":"4.0.0-8.23.1","libvirt-client":"4.0.0-8.23.1","libvirt-daemon":"4.0.0-8.23.1","libvirt-daemon-config-network":"4.0.0-8.23.1","libvirt-daemon-config-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-interface":"4.0.0-8.23.1","libvirt-daemon-driver-libxl":"4.0.0-8.23.1","libvirt-daemon-driver-lxc":"4.0.0-8.23.1","libvirt-daemon-driver-network":"4.0.0-8.23.1","libvirt-daemon-driver-nodedev":"4.0.0-8.23.1","libvirt-daemon-driver-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-qemu":"4.0.0-8.23.1","libvirt-daemon-driver-secret":"4.0.0-8.23.1","libvirt-daemon-driver-storage":"4.0.0-8.23.1","libvirt-daemon-driver-storage-core":"4.0.0-8.23.1","libvirt-daemon-driver-storage-disk":"4.0.0-8.23.1","libvirt-daemon-driver-storage-iscsi":"4.0.0-8.23.1","libvirt-daemon-driver-storage-logical":"4.0.0-8.23.1","libvirt-daemon-driver-storage-mpath":"4.0.0-8.23.1","libvirt-daemon-driver-storage-rbd":"4.0.0-8.23.1","libvirt-daemon-driver-storage-scsi":"4.0.0-8.23.1","libvirt-daemon-hooks":"4.0.0-8.23.1","libvirt-daemon-lxc":"4.0.0-8.23.1","libvirt-daemon-qemu":"4.0.0-8.23.1","libvirt-daemon-xen":"4.0.0-8.23.1","libvirt-doc":"4.0.0-8.23.1","libvirt-libs":"4.0.0-8.23.1","libvirt-lock-sanlock":"4.0.0-8.23.1","libvirt-nss":"4.0.0-8.23.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"libvirt","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.0-8.23.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libvirt":"4.0.0-8.23.1","libvirt-admin":"4.0.0-8.23.1","libvirt-client":"4.0.0-8.23.1","libvirt-daemon":"4.0.0-8.23.1","libvirt-daemon-config-network":"4.0.0-8.23.1","libvirt-daemon-config-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-interface":"4.0.0-8.23.1","libvirt-daemon-driver-libxl":"4.0.0-8.23.1","libvirt-daemon-driver-lxc":"4.0.0-8.23.1","libvirt-daemon-driver-network":"4.0.0-8.23.1","libvirt-daemon-driver-nodedev":"4.0.0-8.23.1","libvirt-daemon-driver-nwfilter":"4.0.0-8.23.1","libvirt-daemon-driver-qemu":"4.0.0-8.23.1","libvirt-daemon-driver-secret":"4.0.0-8.23.1","libvirt-daemon-driver-storage":"4.0.0-8.23.1","libvirt-daemon-driver-storage-core":"4.0.0-8.23.1","libvirt-daemon-driver-storage-disk":"4.0.0-8.23.1","libvirt-daemon-driver-storage-iscsi":"4.0.0-8.23.1","libvirt-daemon-driver-storage-logical":"4.0.0-8.23.1","libvirt-daemon-driver-storage-mpath":"4.0.0-8.23.1","libvirt-daemon-driver-storage-rbd":"4.0.0-8.23.1","libvirt-daemon-driver-storage-scsi":"4.0.0-8.23.1","libvirt-daemon-hooks":"4.0.0-8.23.1","libvirt-daemon-lxc":"4.0.0-8.23.1","libvirt-daemon-qemu":"4.0.0-8.23.1","libvirt-daemon-xen":"4.0.0-8.23.1","libvirt-doc":"4.0.0-8.23.1","libvirt-libs":"4.0.0-8.23.1","libvirt-lock-sanlock":"4.0.0-8.23.1","libvirt-nss":"4.0.0-8.23.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","name":"libvirt","purl":"pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.0.0-8.23.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for libvirt fixes the following issues:\n\n- CVE-2020-15708: Added a  note to libvirtd.conf about polkit auth in SUSE distros (bsc#1174955).\n- CVE-2020-25637: Fixed a double free in qemuAgentGetInterfaces() (bsc#1177155).\n- libxl: Fixed lock manager lock ordering (bsc#1171701).\n","id":"SUSE-SU-2020:3038-1","modified":"2020-10-27T08:08:14Z","published":"2020-10-27T08:08:14Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20203038-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171701"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177155"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-25637"}],"related":["CVE-2020-15708","CVE-2020-25637"],"summary":"Security update for libvirt","upstream":["CVE-2020-15708","CVE-2020-25637"]}