It was found that augeas does incorrect escaping in aug_escape_name() function causing denial-of-service. Product bug: https://bugzilla.redhat.com/show_bug.cgi?id=1475621
Acknowledgments: Name: Han Han (Red Hat)
Upstream patch: https://github.com/hercules-team/augeas/pull/480
Since the patch is already public, going for immediate disclosure on this. Rated as Important due to exposure in libvirtd. The above patch includes good test coverage, so no further test/repro is required for QE.
Created augeas tracking bugs for this issue: Affects: fedora-all [bug 1482340]
Upstream release 1.8.1 contains the fix for this issue: https://github.com/hercules-team/augeas/releases/tag/release-1.8.1 Tarball available from: http://download.augeas.net/
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:2788 https://access.redhat.com/errata/RHSA-2017:2788
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.3 Advanced Update Support Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions Red Hat Enterprise Linux 7.3 Telco Extended Update Support Via RHSA-2019:2403 https://access.redhat.com/errata/RHSA-2019:2403