]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
api: disallow virDomainManagedSaveDefineXML on read-only connections
authorJán Tomko <jtomko@redhat.com>
Fri, 14 Jun 2019 07:14:53 +0000 (09:14 +0200)
committerJán Tomko <jtomko@redhat.com>
Thu, 20 Jun 2019 11:50:56 +0000 (13:50 +0200)
The virDomainManagedSaveDefineXML can be used to alter the domain's
config used for managedsave or even execute arbitrary emulator binaries.
Forbid it on read-only connections.

Fixes: CVE-2019-10166
Reported-by: Matthias Gerstner <mgerstner@suse.de>
Signed-off-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
src/libvirt-domain.c

index b15726caa9e253560e5c23f9ec06d3357a77f3c4..6355f497ce4eb5df9b98cadfc8a96b6615652143 100644 (file)
@@ -9570,6 +9570,7 @@ virDomainManagedSaveDefineXML(virDomainPtr domain, const char *dxml,
 
     virCheckDomainReturn(domain, -1);
     conn = domain->conn;
+    virCheckReadOnlyGoto(conn->flags, error);
 
     if (conn->driver->domainManagedSaveDefineXML) {
         int ret;