On Mon, Sep 16, 2013 at 3:41 PM, Eric Blake wrote: > On 09/15/2013 07:55 AM, Gianluca Cecchi wrote: >> I'm using what stock f18 repo gives today: >> [root@tekkaman ~]# rpm -q libvirt >> libvirt-0.10.2.7-1.fc18.x86_64 > > Known bug: CVE-2013-4291. Downgrade to 0.10.2.6, or wait for 0.10.2.8 > to be released. > > -- > Eric Blake eblake redhat com +1-919-301-3266 > Libvirt virtualization library http://libvirt.org > thanks. Uhm, not so easy. It seems it wants to downgrade to 0.10.2.2-3 (why?) and not 0.10.2.6 and vdsm complains about that.... Where to eventually find intermediate updates? I only found latest ones (so the broken ones...) on mirrors? On my system [g.cecchi@tekkaman ~]$ sudo yum downgrade libvirt-daemon-driver-storage libvirt-daemon-driver-lxc libvirt-daemon-driver-qemu libvirt-daemon-kvm libvirt-daemon-driver-network libvirt-daemon-driver-uml libvirt-lock-sanlock libvirt libvirt-python libvirt-daemon-driver-nwfilter libvirt-daemon-driver-libxl libvirt-client libvirt-daemon-driver-secret libvirt-daemon-config-nwfilter libvirt-daemon-driver-nodedev libvirt-daemon-config-network libvirt-daemon libvirt-daemon-driver-interface libvirt-daemon-driver-xen Loaded plugins: fastestmirror, langpacks, presto, refresh-packagekit, versionlock Loading mirror speeds from cached hostfile * fedora: mirror.switch.ch * livna: ftp-stud.fht-esslingen.de * rpmfusion-free: mirror.switch.ch * rpmfusion-free-updates: mirror.switch.ch * rpmfusion-nonfree: mirror.switch.ch * rpmfusion-nonfree-updates: mirror.switch.ch * updates: mirror.switch.ch Resolving Dependencies --> Running transaction check ---> Package libvirt.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-client.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-client.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-config-network.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-config-network.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-config-nwfilter.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-config-nwfilter.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-interface.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-interface.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-libxl.x86_64 0:0.10.2.7-1.fc18 will be obsoleted ---> Package libvirt-daemon-driver-lxc.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-lxc.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-network.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-network.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-nodedev.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-nodedev.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-nwfilter.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-nwfilter.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-qemu.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-qemu.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-secret.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-secret.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-storage.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-storage.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-uml.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-uml.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-driver-xen.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-driver-xen.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-daemon-kvm.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-daemon-kvm.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-lock-sanlock.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-lock-sanlock.x86_64 0:0.10.2.7-1.fc18 will be erased ---> Package libvirt-python.x86_64 0:0.10.2.2-3.fc18 will be a downgrade ---> Package libvirt-python.x86_64 0:0.10.2.7-1.fc18 will be erased --> Finished Dependency Resolution Error: Package: vdsm-4.10.3-17.fc18.x86_64 (@ovirt-stable) Requires: libvirt >= 0.10.2.4-1 Removing: libvirt-0.10.2.7-1.fc18.x86_64 (@updates) libvirt = 0.10.2.7-1.fc18 Downgraded By: libvirt-0.10.2.2-3.fc18.x86_64 (fedora) libvirt = 0.10.2.2-3.fc18 You could try using --skip-broken to work around the problem You could try running: rpm -Va --nofiles --nodigest -- libvir-list mailing list libvir-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/libvir-list