[libvirt] [PATCH 0/4] disallow multiple APIs on read-only connections

Ján Tomko posted 4 patches 4 years, 10 months ago
Test syntax-check passed
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/libvirt tags/patchew/cover.1561032101.git.jtomko@redhat.com
src/libvirt-domain.c         | 13 ++++---------
src/libvirt-host.c           |  2 ++
src/qemu/qemu_driver.c       |  2 +-
src/remote/remote_protocol.x |  3 +--
4 files changed, 8 insertions(+), 12 deletions(-)
[libvirt] [PATCH 0/4] disallow multiple APIs on read-only connections
Posted by Ján Tomko 4 years, 10 months ago
One patch per CVE for:
CVE-2019-10161
CVE-2019-10166
CVE-2019-10167
CVE-2019-10168

Ján Tomko (4):
  api: disallow virDomainSaveImageGetXMLDesc on read-only connections
  api: disallow virDomainManagedSaveDefineXML on read-only connections
  api: disallow virConnectGetDomainCapabilities on read-only connections
  api: disallow virConnect*HypervisorCPU on read-only connections

 src/libvirt-domain.c         | 13 ++++---------
 src/libvirt-host.c           |  2 ++
 src/qemu/qemu_driver.c       |  2 +-
 src/remote/remote_protocol.x |  3 +--
 4 files changed, 8 insertions(+), 12 deletions(-)

Now pushed.
-- 
2.20.1

--
libvir-list mailing list
libvir-list@redhat.com
https://www.redhat.com/mailman/listinfo/libvir-list