]> git.ipfire.org Git - thirdparty/libvirt.git/commit
libxl: Check ACLs before parsing the whole domain XML
authorMartin Kletzander <mkletzan@redhat.com>
Thu, 6 Nov 2025 14:43:57 +0000 (15:43 +0100)
committerMartin Kletzander <mkletzan@redhat.com>
Wed, 12 Nov 2025 08:50:56 +0000 (09:50 +0100)
commita1f48bca077e2f3377f29d746efd4310b8a2910f
tree2c88947dab9659c17ee61d2c41d056845d43c068
parentb45f10bc0a2f30ccdbf2cb55da2e4f85b3ebfb23
libxl: Check ACLs before parsing the whole domain XML

Utilise the new virDomainDefIDsParseString() for that.

Fixes: CVE-2025-12748
Reported-by: Святослав Терешин <s.tereshin@fobos-nt.ru>
Signed-off-by: Martin Kletzander <mkletzan@redhat.com>
Reviewed-by: Michal Privoznik <mprivozn@redhat.com>
src/libxl/libxl_driver.c