Comment 4 for bug 1710341

Revision history for this message
Trent Lloyd (lathiat) wrote :

I identified that most likely there was minimal security impact, however I reported the issue upstream via the security contact anyway. They generally agreed exploit-ability didn't seem likely and so have simply applied a patch to stop using the bad RNG.

https://www.redhat.com/archives/libvirt-users/2018-May/msg00097.html
https://www.redhat.com/archives/libvirt-users/2018-May/msg00100.html

Setting this bug public and updating it with an SRU request to apply the upstream applied patch.