mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2024-12-22 05:35:25 +00:00
news: Document recent CVE fix
Document the fix of leaking /dev/mapper/control to QEMU (fixed in v6.6.0-rc1-3-g2249455654). Signed-off-by: Michal Privoznik <mprivozn@redhat.com> Reviewed-by: Andrea Bolognani <abologna@redhat.com>
This commit is contained in:
parent
0e6dcc2f52
commit
957107184f
7
NEWS.rst
7
NEWS.rst
@ -33,6 +33,13 @@ v6.6.0 (unreleased)
|
||||
|
||||
* **Bug fixes**
|
||||
|
||||
* virdevmapper: Don't use libdevmapper to obtain dependencies
|
||||
|
||||
When building domain's private ``/dev`` in a namespace, libdevmapper was
|
||||
consulted for getting full dependency tree of domain's disks. However, this
|
||||
meant that libdevmapper opened ``/dev/mapper/control`` which wasn't closed
|
||||
and was leaked to QEMU. CVE-2020-14339
|
||||
|
||||
|
||||
v6.5.0 (2020-07-03)
|
||||
===================
|
||||
|
Loading…
Reference in New Issue
Block a user