Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20485

Опубликовано: 05 дек. 2019
Источник: redhat
CVSS3: 5.8

Описание

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

A flaw was found in the way the libvirtd daemon issued the 'suspend' command to a QEMU guest-agent running inside a guest, where it holds a monitor job while issuing the 'suspend' command to a guest-agent. A malicious guest-agent may use this flaw to block the libvirt daemon indefinitely, resulting in a denial of service.

Отчет

This issue affects the version of the libvirt package as shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt updates for Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue. Red Hat Enterprise Linux version 5 and 6 are in Maintenance Support 2 Phase of the life cycle. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of the Red Hat Enterprise Linux version 5 and 6. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtOut of support scope
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.1/libvirtAffected
Advanced Virtualization for RHEL 8.2.0virtFixedRHBA-2020:201705.05.2020
Advanced Virtualization for RHEL 8.2.0virt-develFixedRHBA-2020:201705.05.2020
Red Hat Enterprise Linux 7libvirtFixedRHSA-2020:400029.09.2020
Red Hat Enterprise Linux 8virt-develFixedRHSA-2020:467604.11.2020
Red Hat Enterprise Linux 8virtFixedRHSA-2020:467604.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1809740libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
nvd
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

CVSS3: 5.7
debian
больше 5 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a ...

CVSS3: 5.7
github
около 3 лет назад

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

oracle-oval
около 5 лет назад

ELSA-2020-5674: libvirt security update (IMPORTANT)

5.8 Medium

CVSS3