CVE-2018-1064

Priority
Description
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as
a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor
but now also triggered via QEMU guest agent.
Notes
Package
Upstream:released (4.1.0-1)
Ubuntu 12.04 ESM (Precise Pangolin):needs-triage
Ubuntu 14.04 ESM (Trusty Tahr):released (1.2.2-0ubuntu13.1.27)
Ubuntu 16.04 LTS (Xenial Xerus):released (1.3.1-1ubuntu10.24)
Ubuntu 18.04 LTS (Bionic Beaver):released (4.0.0-1ubuntu8.2)
Ubuntu 19.04 (Disco Dingo):not-affected (5.0.0-1ubuntu2)
Ubuntu 19.10 (Eoan):not-affected (5.0.0-1ubuntu2)
Patches:
Upstream:https://libvirt.org/git/?p=libvirt.git;a=commit;h=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513
More Information

Updated: 2019-10-18 02:35:57 UTC (commit cccfc4426d8c1fbf582a89d981fe7fc812124543)