Описание
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
A flaw was found in the way the libvirtd daemon issued the 'suspend' command to a QEMU guest-agent running inside a guest, where it holds a monitor job while issuing the 'suspend' command to a guest-agent. A malicious guest-agent may use this flaw to block the libvirt daemon indefinitely, resulting in a denial of service.
Отчет
This issue affects the version of the libvirt package as shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt updates for Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue. Red Hat Enterprise Linux version 5 and 6 are in Maintenance Support 2 Phase of the life cycle. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of the Red Hat Enterprise Linux version 5 and 6. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | libvirt | Out of support scope | ||
Red Hat Enterprise Linux 6 | libvirt | Out of support scope | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/libvirt | Affected | ||
Advanced Virtualization for RHEL 8.2.0 | virt | Fixed | RHBA-2020:2017 | 05.05.2020 |
Advanced Virtualization for RHEL 8.2.0 | virt-devel | Fixed | RHBA-2020:2017 | 05.05.2020 |
Red Hat Enterprise Linux 7 | libvirt | Fixed | RHSA-2020:4000 | 29.09.2020 |
Red Hat Enterprise Linux 8 | virt-devel | Fixed | RHSA-2020:4676 | 04.11.2020 |
Red Hat Enterprise Linux 8 | virt | Fixed | RHSA-2020:4676 | 04.11.2020 |
Показывать по
Дополнительная информация
Статус:
5.8 Medium
CVSS3
Связанные уязвимости
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a ...
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
5.8 Medium
CVSS3