Page 1 of 1

[CVE-2018-3639] libvirt rpm package for CentOS 6.8

Posted: 2018/07/18 13:20:04
by arun168403
Hi,

Our application is running on top of CentOS6.8.
During our search for solution to CVE-2018-3639 of CentOS patches we find the libvirt-0.10.2-62.el6_9.2.x86_64.rpm is available only for CentOS 6.9.

Could you kindly confirm whether this package can be installed on top of CentOS 6.8 as well?

If not, could you suggest which version of rpm can be used for CentOS6.8 which has fix for CVE-2018-3639.

Regards,
Arun

Re: [CVE-2018-3639] libvirt rpm package for CentOS 6.8

Posted: 2018/07/18 13:41:23
by avij
We stopped shipping updates for 6.8 when 6.9 was released upstream, and also stopped releasing updates for 6.9 when 6.10 was released upstream. Older releases than 6.10 are not supported.

Actually, what you would want is libvirt-0.10.2-64.el6.x86_64.rpm. This is included in CentOS 6.10 and fixes CVE-2018-3639.

As for if it can be installed on 6.8 .. maybe? I would suggest upgrading one of your test servers (running your application) to 6.10 to see if there are any issues. If not, I'd suggest updating all your other servers to 6.10 as well.

Re: [CVE-2018-3639] libvirt rpm package for CentOS 6.8

Posted: 2018/07/18 14:02:32
by TrevorH
Please be aware that only the most recent point release of CentOS receives updates. Once a new point release comes out, all previous ones are obsolete and need to be updated to the new one.