Описание
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
It was found that QEMU's qemuDomainMigratePerform() and qemuDomainMigrateFinish2() functions did not correctly perform a domain unlock on a failed ACL check. A remote attacker able to establish a connection to libvirtd could use this flaw to lock a domain of a more privileged user, causing a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | libvirt | Under investigation | ||
Red Hat Enterprise Linux 6 | libvirt | Under investigation | ||
Red Hat Storage 2.1 | libvirt | Will not fix | ||
Red Hat Enterprise Linux 7 | libvirt | Fixed | RHSA-2015:0323 | 05.03.2015 |
Red Hat Gluster Storage 3.1 for RHEL 7 | libvirt | Fixed | RHSA-2015:0323 | 05.03.2015 |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | libvirt | Fixed | RHSA-2015:0323 | 05.03.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
1.8 Low
CVSS2
Связанные уязвимости
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 func ...
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
ELSA-2015-0323: libvirt security, bug fix, and enhancement update (LOW)
EPSS
1.8 Low
CVSS2