From f5c10753525315ab4ea3a68882326ead6803bbeb Mon Sep 17 00:00:00 2001 From: Jiri Denemark Date: Fri, 14 Aug 2026 15:17:08 +0200 Subject: [PATCH] libvirt-11.10.0-17.el9 - conf: schemas: Allow '.' in schema for CPU flag name (RHEL-222551) - tests: capabilityschemadata: Add a real test example (RHEL-222551) - util: virFileChownFiles: do not follow symlinks (CVE-2026-63622) Resolves: RHEL-222551, RHEL-235940 --- ...-Allow-.-in-schema-for-CPU-flag-name.patch | 38 + ...tyschemadata-Add-a-real-test-example.patch | 1063 +++++++++++++++++ ...ileChownFiles-do-not-follow-symlinks.patch | 71 ++ libvirt.spec | 10 +- 4 files changed, 1181 insertions(+), 1 deletion(-) create mode 100644 libvirt-conf-schemas-Allow-.-in-schema-for-CPU-flag-name.patch create mode 100644 libvirt-tests-capabilityschemadata-Add-a-real-test-example.patch create mode 100644 libvirt-util-virFileChownFiles-do-not-follow-symlinks.patch diff --git a/libvirt-conf-schemas-Allow-.-in-schema-for-CPU-flag-name.patch b/libvirt-conf-schemas-Allow-.-in-schema-for-CPU-flag-name.patch new file mode 100644 index 0000000..e77dc68 --- /dev/null +++ b/libvirt-conf-schemas-Allow-.-in-schema-for-CPU-flag-name.patch @@ -0,0 +1,38 @@ +From 0c8a9769c18f6da3a91e6186833710d32a8f26d6 Mon Sep 17 00:00:00 2001 +Message-ID: <0c8a9769c18f6da3a91e6186833710d32a8f26d6.1786713428.git.jdenemar@redhat.com> +From: Peter Krempa +Date: Mon, 3 Aug 2026 14:53:25 +0200 +Subject: [PATCH] conf: schemas: Allow '.' in schema for CPU flag name +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Allow '.' so that CPU features such as: + + + +pass schema validation. + +Signed-off-by: Peter Krempa +Reviewed-by: Ján Tomko +(cherry picked from commit 5225c1cb688170bb2748f2f23455da4a7cb8a1bf) +https://redhat.atlassian.net/browse/RHEL-222551 +--- + src/conf/schemas/cputypes.rng | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/conf/schemas/cputypes.rng b/src/conf/schemas/cputypes.rng +index 8edf1d14e3..eef3807f1a 100644 +--- a/src/conf/schemas/cputypes.rng ++++ b/src/conf/schemas/cputypes.rng +@@ -406,7 +406,7 @@ + + + +- [a-zA-Z0-9\-_]+ ++ [a-zA-Z0-9\-_.]+ + + + +-- +2.55.0 diff --git a/libvirt-tests-capabilityschemadata-Add-a-real-test-example.patch b/libvirt-tests-capabilityschemadata-Add-a-real-test-example.patch new file mode 100644 index 0000000..ee92bd3 --- /dev/null +++ b/libvirt-tests-capabilityschemadata-Add-a-real-test-example.patch @@ -0,0 +1,1063 @@ +From 9c8cd42553ec6d84018d068875dbd0cfddf6e78c Mon Sep 17 00:00:00 2001 +Message-ID: <9c8cd42553ec6d84018d068875dbd0cfddf6e78c.1786713428.git.jdenemar@redhat.com> +From: Peter Krempa +Date: Fri, 31 Jul 2026 16:26:33 +0200 +Subject: [PATCH] tests: capabilityschemadata: Add a real test example +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Data obtained by running: + + virsh -q capabilities > tests/capabilityschemadata/caps-qemu-real-full.xml + +Signed-off-by: Peter Krempa +Reviewed-by: Ján Tomko +(cherry picked from commit e3da3cf552513e7253294b40f634228918902635) +https://redhat.atlassian.net/browse/RHEL-222551 +--- + .../caps-qemu-real-full.xml | 1033 +++++++++++++++++ + 1 file changed, 1033 insertions(+) + create mode 100644 tests/capabilityschemadata/caps-qemu-real-full.xml + +diff --git a/tests/capabilityschemadata/caps-qemu-real-full.xml b/tests/capabilityschemadata/caps-qemu-real-full.xml +new file mode 100644 +index 0000000000..369101201b +--- /dev/null ++++ b/tests/capabilityschemadata/caps-qemu-real-full.xml +@@ -0,0 +1,1033 @@ ++ ++ ++ ++ 29fb382a-ac39-8995-b33c-bcfce7b79434 ++ ++ x86_64 ++ Opteron_G3-v1 ++ AMD ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ tcp ++ rdma ++ ++ ++ ++ ++ ++ 63393224 ++ 15848306 ++ 0 ++ 0 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ selinux ++ 0 ++ system_u:system_r:svirt_t:s0 ++ system_u:system_r:svirt_tcg_t:s0 ++ ++ ++ dac ++ 0 ++ +107:+107 ++ +107:+107 ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-arm ++ virt-11.0 ++ virt ++ mori-bmc ++ ast2600-evb ++ qcom-dc-scm-v1-bmc ++ tiogapass-bmc ++ catalina-bmc ++ nuri ++ mcimx7d-sabre ++ mps3-an536 ++ romulus-bmc ++ npcm750-evb ++ rainier-bmc ++ mps3-an547 ++ realview-pbx-a9 ++ kzm ++ musca-b1 ++ versatileab ++ b-l475e-iot01a ++ fby35-bmc ++ musca-a ++ mcimx6ul-evk ++ virt-5.1 ++ virt-10.0 ++ smdkc210 ++ sx1 ++ imx25-pdk ++ stm32vldiscovery ++ orangepi-pc ++ quanta-q71l-bmc ++ virt-5.2 ++ virt-10.1 ++ xilinx-zynq-a9 ++ mps2-an500 ++ mps2-an521 ++ sabrelite ++ mps2-an511 ++ canon-a1100 ++ realview-eb ++ quanta-gbs-bmc ++ emcraft-sf2 ++ virt-10.2 ++ realview-pb-a8 ++ yosemitev2-bmc ++ virt-7.0 ++ virt-9.0 ++ raspi1ap ++ palmetto-bmc ++ sx1-v1 ++ gb200nvl-bmc ++ g220a-bmc ++ virt-7.1 ++ virt-9.1 ++ bletchley-bmc ++ quanta-gsj ++ versatilepb ++ realview-eb-mpcore ++ integratorcp ++ virt-7.2 ++ supermicrox11-bmc ++ virt-9.2 ++ witherspoon-bmc ++ qcom-firework-bmc ++ mps3-an524 ++ kudo-bmc ++ vexpress-a9 ++ musicpal ++ lm3s811evb ++ lm3s6965evb ++ supermicro-x11spi-bmc ++ microbit ++ fby35 ++ mps2-an385 ++ mps2-an505 ++ virt-6.0 ++ virt-8.0 ++ cubieboard ++ ast1030-evb ++ bpim2u ++ netduino2 ++ ast1060-evb ++ mps2-an386 ++ olimex-stm32-h405 ++ virt-6.1 ++ virt-8.1 ++ raspi2b ++ vexpress-a15 ++ virt-6.2 ++ fuji-bmc ++ max78000fthr ++ virt-8.2 ++ sonorapass-bmc ++ ast2500-evb ++ netduinoplus2 ++ collie ++ raspi0 ++ fp5280g2-bmc ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-arm ++ virt-11.0 ++ virt ++ mori-bmc ++ ast2600-evb ++ qcom-dc-scm-v1-bmc ++ tiogapass-bmc ++ catalina-bmc ++ nuri ++ mcimx7d-sabre ++ mps3-an536 ++ romulus-bmc ++ npcm750-evb ++ rainier-bmc ++ mps3-an547 ++ realview-pbx-a9 ++ kzm ++ musca-b1 ++ versatileab ++ b-l475e-iot01a ++ fby35-bmc ++ musca-a ++ mcimx6ul-evk ++ virt-5.1 ++ virt-10.0 ++ smdkc210 ++ sx1 ++ imx25-pdk ++ stm32vldiscovery ++ orangepi-pc ++ quanta-q71l-bmc ++ virt-5.2 ++ virt-10.1 ++ xilinx-zynq-a9 ++ mps2-an500 ++ mps2-an521 ++ sabrelite ++ mps2-an511 ++ canon-a1100 ++ realview-eb ++ quanta-gbs-bmc ++ emcraft-sf2 ++ virt-10.2 ++ realview-pb-a8 ++ yosemitev2-bmc ++ virt-7.0 ++ virt-9.0 ++ raspi1ap ++ palmetto-bmc ++ sx1-v1 ++ gb200nvl-bmc ++ g220a-bmc ++ virt-7.1 ++ virt-9.1 ++ bletchley-bmc ++ quanta-gsj ++ versatilepb ++ realview-eb-mpcore ++ integratorcp ++ virt-7.2 ++ supermicrox11-bmc ++ virt-9.2 ++ witherspoon-bmc ++ qcom-firework-bmc ++ mps3-an524 ++ kudo-bmc ++ vexpress-a9 ++ musicpal ++ lm3s811evb ++ lm3s6965evb ++ supermicro-x11spi-bmc ++ microbit ++ fby35 ++ mps2-an385 ++ mps2-an505 ++ virt-6.0 ++ virt-8.0 ++ cubieboard ++ ast1030-evb ++ bpim2u ++ netduino2 ++ ast1060-evb ++ mps2-an386 ++ olimex-stm32-h405 ++ virt-6.1 ++ virt-8.1 ++ raspi2b ++ vexpress-a15 ++ virt-6.2 ++ fuji-bmc ++ max78000fthr ++ virt-8.2 ++ sonorapass-bmc ++ ast2500-evb ++ netduinoplus2 ++ collie ++ raspi0 ++ fp5280g2-bmc ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-aarch64 ++ virt-11.0 ++ virt ++ mori-bmc ++ qcom-dc-scm-v1-bmc ++ ast2600-evb ++ tiogapass-bmc ++ catalina-bmc ++ ast2700fc ++ nuri ++ mcimx7d-sabre ++ mps3-an536 ++ romulus-bmc ++ npcm750-evb ++ rainier-bmc ++ mps3-an547 ++ realview-pbx-a9 ++ kzm ++ musca-b1 ++ versatileab ++ b-l475e-iot01a ++ fby35-bmc ++ musca-a ++ mcimx6ul-evk ++ virt-5.1 ++ virt-10.0 ++ smdkc210 ++ sx1 ++ imx25-pdk ++ imx8mp-evk ++ stm32vldiscovery ++ orangepi-pc ++ quanta-q71l-bmc ++ virt-5.2 ++ virt-10.1 ++ xilinx-zynq-a9 ++ xlnx-zcu102 ++ mps2-an500 ++ mps2-an521 ++ sabrelite ++ mps2-an511 ++ canon-a1100 ++ realview-eb ++ quanta-gbs-bmc ++ emcraft-sf2 ++ virt-10.2 ++ realview-pb-a8 ++ yosemitev2-bmc ++ sbsa-ref ++ virt-7.0 ++ virt-9.0 ++ amd-versal-virt ++ xlnx-versal-virt ++ raspi1ap ++ palmetto-bmc ++ sx1-v1 ++ gb200nvl-bmc ++ g220a-bmc ++ virt-7.1 ++ virt-9.1 ++ bletchley-bmc ++ quanta-gsj ++ versatilepb ++ npcm845-evb ++ realview-eb-mpcore ++ integratorcp ++ virt-7.2 ++ supermicrox11-bmc ++ virt-9.2 ++ witherspoon-bmc ++ qcom-firework-bmc ++ mps3-an524 ++ kudo-bmc ++ vexpress-a9 ++ musicpal ++ lm3s811evb ++ lm3s6965evb ++ supermicro-x11spi-bmc ++ ast2700a1-evb ++ microbit ++ fby35 ++ mps2-an385 ++ mps2-an505 ++ virt-6.0 ++ virt-8.0 ++ amd-versal2-virt ++ raspi3ap ++ cubieboard ++ ast2700a2-evb ++ ast2700-evb ++ ast1030-evb ++ bpim2u ++ netduino2 ++ ast1060-evb ++ raspi4b ++ mps2-an386 ++ olimex-stm32-h405 ++ virt-6.1 ++ virt-8.1 ++ raspi3b ++ raspi2b ++ vexpress-a15 ++ virt-6.2 ++ fuji-bmc ++ max78000fthr ++ virt-8.2 ++ sonorapass-bmc ++ ast2500-evb ++ netduinoplus2 ++ collie ++ raspi0 ++ fp5280g2-bmc ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-i386 ++ pc-i440fx-11.0 ++ pc ++ pc-q35-5.2 ++ pc-i440fx-10.2 ++ xenpv ++ pc-i440fx-6.2 ++ pc-i440fx-5.2 ++ pc-q35-9.1 ++ pc-q35-7.1 ++ pc-q35-8.1 ++ pc-q35-11.0 ++ q35 ++ pc-i440fx-8.1 ++ pc-q35-6.1 ++ pc-i440fx-9.1 ++ pc-q35-10.0 ++ pc-i440fx-7.1 ++ x-remote ++ pc-i440fx-10.1 ++ pc-q35-5.1 ++ pc-i440fx-6.1 ++ pc-i440fx-5.1 ++ isapc ++ pc-q35-9.0 ++ pc-q35-10.2 ++ pc-q35-7.0 ++ pc-q35-8.0 ++ pc-i440fx-8.0 ++ pc-q35-6.0 ++ pc-i440fx-9.0 ++ pc-i440fx-7.0 ++ nitro-enclave ++ xenpvh ++ pc-i440fx-10.0 ++ pc-q35-9.2 ++ pc-q35-7.2 ++ pc-i440fx-6.0 ++ xenfv-4.2 ++ microvm ++ pc-q35-8.2 ++ pc-i440fx-8.2 ++ pc-q35-6.2 ++ pc-i440fx-9.2 ++ pc-q35-10.1 ++ pc-i440fx-7.2 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-mips ++ malta ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-mipsel ++ malta ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-mips64 ++ malta ++ pica61 ++ magnum ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-mips64el ++ malta ++ loongson3-virt ++ pica61 ++ magnum ++ boston ++ fuloong2e ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-ppc ++ g3beige ++ ppe42_machine ++ amigaone ++ virtex-ml507 ++ mac99 ++ ppce500 ++ sam460ex ++ pegasos2 ++ bamboo ++ 40p ++ pegasos1 ++ mpc8544ds ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-ppc64 ++ pseries-11.0 ++ pseries ++ amigaone ++ powernv9 ++ mpc8544ds ++ pseries-6.1 ++ ppe42_machine ++ powernv10 ++ powernv ++ pseries-6.2 ++ powernv11 ++ ppce500 ++ pegasos1 ++ powernv10-rainier ++ powernv ++ pseries-8.0 ++ 40p ++ pegasos2 ++ pseries-8.1 ++ pseries-5.1 ++ bamboo ++ g3beige ++ pseries-8.2 ++ pseries-5.2 ++ pseries-7.0 ++ virtex-ml507 ++ pseries-9.0 ++ pseries-10.0 ++ pseries-7.1 ++ pseries-9.1 ++ pseries-10.1 ++ pseries-7.2 ++ mac99 ++ pseries-9.2 ++ sam460ex ++ pseries-10.2 ++ powernv8 ++ pseries-6.0 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-ppc64 ++ pseries-11.0 ++ pseries ++ amigaone ++ powernv9 ++ mpc8544ds ++ pseries-6.1 ++ ppe42_machine ++ powernv10 ++ powernv ++ pseries-6.2 ++ powernv11 ++ ppce500 ++ pegasos1 ++ powernv10-rainier ++ powernv ++ pseries-8.0 ++ 40p ++ pegasos2 ++ pseries-8.1 ++ pseries-5.1 ++ bamboo ++ g3beige ++ pseries-8.2 ++ pseries-5.2 ++ pseries-7.0 ++ virtex-ml507 ++ pseries-9.0 ++ pseries-10.0 ++ pseries-7.1 ++ pseries-9.1 ++ pseries-10.1 ++ pseries-7.2 ++ mac99 ++ pseries-9.2 ++ sam460ex ++ pseries-10.2 ++ powernv8 ++ pseries-6.0 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-riscv32 ++ virt ++ spike ++ opentitan ++ sifive_u ++ amd-microblaze-v-generic ++ sifive_e ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-riscv64 ++ virt ++ spike ++ boston-aia ++ xiangshan-kunminghu ++ sifive_u ++ microchip-icicle-kit ++ amd-microblaze-v-generic ++ shakti_c ++ sifive_e ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-s390x ++ s390-ccw-virtio-11.0 ++ s390-ccw-virtio ++ s390-ccw-virtio-8.0 ++ s390-ccw-virtio-6.0 ++ s390-ccw-virtio-7.0 ++ s390-ccw-virtio-9.2 ++ s390-ccw-virtio-10.1 ++ s390-ccw-virtio-8.2 ++ s390-ccw-virtio-6.2 ++ s390-ccw-virtio-7.2 ++ s390-ccw-virtio-5.2 ++ s390-ccw-virtio-9.1 ++ s390-ccw-virtio-10.0 ++ s390-ccw-virtio-8.1 ++ s390-ccw-virtio-6.1 ++ s390-ccw-virtio-7.1 ++ s390-ccw-virtio-5.1 ++ s390-ccw-virtio-10.2 ++ s390-ccw-virtio-9.0 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 32 ++ /usr/bin/qemu-system-sparc ++ SS-5 ++ SS-20 ++ LX ++ SPARCClassic ++ leon3_generic ++ SPARCbook ++ SS-4 ++ SS-600MP ++ SS-10 ++ Voyager ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-sparc64 ++ sun4u ++ niagara ++ sun4v ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ hvm ++ ++ 64 ++ /usr/bin/qemu-system-x86_64 ++ pc-i440fx-11.0 ++ pc ++ pc-q35-5.2 ++ pc-i440fx-10.2 ++ xenpv ++ pc-i440fx-6.2 ++ pc-i440fx-5.2 ++ pc-q35-9.1 ++ pc-q35-7.1 ++ pc-q35-8.1 ++ pc-q35-11.0 ++ q35 ++ pc-i440fx-8.1 ++ pc-q35-6.1 ++ nitro ++ pc-i440fx-9.1 ++ pc-q35-10.0 ++ pc-i440fx-7.1 ++ x-remote ++ pc-i440fx-10.1 ++ pc-q35-5.1 ++ pc-i440fx-6.1 ++ pc-i440fx-5.1 ++ isapc ++ pc-q35-9.0 ++ pc-q35-10.2 ++ pc-q35-7.0 ++ pc-q35-8.0 ++ pc-i440fx-8.0 ++ pc-q35-6.0 ++ pc-i440fx-9.0 ++ pc-i440fx-7.0 ++ nitro-enclave ++ xenpvh ++ pc-i440fx-10.0 ++ pc-q35-9.2 ++ pc-q35-7.2 ++ pc-i440fx-6.0 ++ xenfv-4.2 ++ microvm ++ pc-q35-8.2 ++ pc-i440fx-8.2 ++ pc-q35-6.2 ++ pc-i440fx-9.2 ++ pc-q35-10.1 ++ pc-i440fx-7.2 ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ ++ +-- +2.55.0 diff --git a/libvirt-util-virFileChownFiles-do-not-follow-symlinks.patch b/libvirt-util-virFileChownFiles-do-not-follow-symlinks.patch new file mode 100644 index 0000000..61644c5 --- /dev/null +++ b/libvirt-util-virFileChownFiles-do-not-follow-symlinks.patch @@ -0,0 +1,71 @@ +From b71d798b0e6fb719ae6c05ccf02fc0a3f7e57e6a Mon Sep 17 00:00:00 2001 +Message-ID: +From: =?UTF-8?q?HE=20WEI=EF=BC=88=E3=82=AE=E3=82=AB=E3=82=AF=EF=BC=89?= + +Date: Tue, 28 Jul 2026 17:49:02 +0100 +Subject: [PATCH] util: virFileChownFiles: do not follow symlinks +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +virFileChownFiles() selected entries with virFileIsRegular() (stat(), follows +symlinks) and changed ownership with chown() (follows symlinks). A component +that owns the target directory at a lower privilege (e.g. the swtpm/tss state +directory) can plant a symlink to an arbitrary regular file and have the root +caller chown that file. Use lstat() to skip non-regular entries and +fchownat(..., AT_SYMLINK_NOFOLLOW) so a symlink final component is never +followed. + +Fixes: CVE-2026-63622 +Signed-off-by: HE WEI(ギカク) +[DB: use g_lstat instead of stat; use lchown instead of + fchownat for portability; added comment] +Reviewed-by: Ján Tomko +Signed-off-by: Daniel P. Berrangé +(cherry picked from commit 801160fd414ca2cc402bc01ead09b7ed4c3b8f5b) +Signed-off-by: Jiri Denemark +--- + src/util/virfile.c | 16 ++++++++++++++-- + 1 file changed, 14 insertions(+), 2 deletions(-) + +diff --git a/src/util/virfile.c b/src/util/virfile.c +index 05b2fa8168..4fbb306a78 100644 +--- a/src/util/virfile.c ++++ b/src/util/virfile.c +@@ -3179,6 +3179,12 @@ int virDirIsEmpty(const char *path, + * + * Change ownership of all regular files in a directory. + * ++ * This will NOT follow any symlinks, to avoid security risks. ++ * It is assumed the process using content under @name will ++ * be unprivileged, thus less trusted than libvirt. If it is ++ * compromised it might attempt to create symlinks in @name to ++ * escalate privileges on a subsequent call to virFileChownFiles. ++ * + * Returns -1 on error, with error already reported, 0 on success. + */ + #ifndef WIN32 +@@ -3195,13 +3201,19 @@ int virFileChownFiles(const char *name, + + while ((direrr = virDirRead(dir, &ent, name)) > 0) { + g_autofree char *path = NULL; ++ struct stat sb; + + path = g_build_filename(name, ent->d_name, NULL); + +- if (!virFileIsRegular(path)) ++ if (g_lstat(path, &sb) < 0) { ++ virReportSystemError(errno, _("cannot stat '%1$s'"), path); ++ return -1; ++ } ++ ++ if (!S_ISREG(sb.st_mode)) + continue; + +- if (chown(path, uid, gid) < 0) { ++ if (lchown(path, uid, gid) < 0) { + virReportSystemError(errno, + _("cannot chown '%1$s' to (%2$u, %3$u)"), + ent->d_name, (unsigned int) uid, +-- +2.55.0 diff --git a/libvirt.spec b/libvirt.spec index d4b1c1a..5422f7a 100644 --- a/libvirt.spec +++ b/libvirt.spec @@ -294,7 +294,7 @@ Summary: Library providing a simple virtualization API Name: libvirt Version: 11.10.0 -Release: 16%{?dist}%{?extra_release} +Release: 17%{?dist}%{?extra_release} License: GPL-2.0-or-later AND LGPL-2.1-only AND LGPL-2.1-or-later AND OFL-1.1 URL: https://libvirt.org/ @@ -442,6 +442,9 @@ Patch137: libvirt-qemuValidateDomainDeviceDefVideo-Fix-checks-of-virtio-video-de Patch138: libvirt-qemuDeviceVideoGetModel-Remove-logic-for-selecting-virtio-devices.patch Patch139: libvirt-qemuDeviceVideoGetModel-Simplify-by-relying-on-checks-from-qemuValidateDomainDeviceDefVideo.patch Patch140: libvirt-qemu-Remove-qemuDomainSupportsVideoVga.patch +Patch141: libvirt-conf-schemas-Allow-.-in-schema-for-CPU-flag-name.patch +Patch142: libvirt-tests-capabilityschemadata-Add-a-real-test-example.patch +Patch143: libvirt-util-virFileChownFiles-do-not-follow-symlinks.patch Requires: libvirt-daemon = %{version}-%{release} @@ -2833,6 +2836,11 @@ exit 0 %endif %changelog +* Fri Aug 14 2026 Jiri Denemark - 11.10.0-17 +- conf: schemas: Allow '.' in schema for CPU flag name (RHEL-222551) +- tests: capabilityschemadata: Add a real test example (RHEL-222551) +- util: virFileChownFiles: do not follow symlinks (CVE-2026-63622) + * Fri Jul 24 2026 Jiri Denemark - 11.10.0-16 - Live migration fails when virtio-vga becomes available, video device switches from virtio-gpu-pci to virtio-vga on target (RHEL-177646)