]> git.ipfire.org Git - thirdparty/libvirt.git/commit
api: disallow virConnect*HypervisorCPU on read-only connections v5.2-maint
authorJán Tomko <jtomko@redhat.com>
Fri, 14 Jun 2019 07:17:39 +0000 (09:17 +0200)
committerJán Tomko <jtomko@redhat.com>
Mon, 24 Jun 2019 07:36:00 +0000 (09:36 +0200)
commit45ae5e529d4e886f47dacca9dfe5a08d95a3425a
tree5265e39de91a8580911ca1622841a79ba9f0b6b5
parent4f50f36c0004af0faf0f535b46e2a1841c2443d8
api: disallow virConnect*HypervisorCPU on read-only connections

These APIs can be used to execute arbitrary emulators.
Forbid them on read-only connections.

Fixes: CVE-2019-10168
Signed-off-by: Ján Tomko <jtomko@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
(cherry picked from commit bf6c2830b6c338b1f5699b095df36f374777b291)
Signed-off-by: Ján Tomko <jtomko@redhat.com>
src/libvirt-host.c