From: Daniel P. Berrange Date: Thu, 19 Jul 2012 14:58:45 +0000 (+0100) Subject: Disable NWFilter driver completely when unprivileged X-Git-Tag: CVE-2012-3445~90 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=f8ab364c;p=thirdparty%2Flibvirt.git Disable NWFilter driver completely when unprivileged Running libvirtd unprivileged results in a warning message from the NWFilter driver virNWFilterSnoopLeaseFileRefresh:1882 : open("/var/run/libvirt/network/nwfilter.ltmp"): No such file or directory Since it requires privileged network access, this driver should not even run when unprivileged. Signed-off-by: Daniel P. Berrange --- diff --git a/src/nwfilter/nwfilter_driver.c b/src/nwfilter/nwfilter_driver.c index 58d91f9d69..9034549360 100644 --- a/src/nwfilter/nwfilter_driver.c +++ b/src/nwfilter/nwfilter_driver.c @@ -68,6 +68,9 @@ static int nwfilterDriverStartup(int privileged) { char *base = NULL; + if (!privileged) + return 0; + if (virNWFilterIPAddrMapInit() < 0) return -1; if (virNWFilterLearnInit() < 0)