Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12430

Опубликовано: 19 фев. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.

A memory leak flaw was found in the libvirt API that is responsible for retrieving domain stats when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.

Отчет

Versions of libvirt as shipped with Red Hat Enterprise Linux are marked as "notaffected" because they do not include the vulnerable code, which was introduced in a later version of the package. Specifically, the affected function qemuDomainGetStatsIOThread() was introduced in libvirt upstream version 4.10.0. RHEL Advanced Virtualization is affected by this flaw as it ships a more recent version of the package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8virt:rhel/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.1/libvirtWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=1828190libvirt: memory leak in domstats may allow read-only user to perform DoS attack

EPSS

Процентиль: 76%
0.00947
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.

CVSS3: 6.5
nvd
почти 6 лет назад

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.

CVSS3: 6.5
debian
почти 6 лет назад

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_dri ...

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.

oracle-oval
больше 5 лет назад

ELSA-2020-5720: libvirt security update (IMPORTANT)

EPSS

Процентиль: 76%
0.00947
Низкий

6.5 Medium

CVSS3