Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3559

Опубликовано: 02 дек. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

A flaw was found in libvirt in the virConnectListAllNodeDevices API. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

Отчет

The versions of libvirt as shipped with Red Hat Enterprise Linux 6, 7, 8, and Red Hat Enterprise Linux Advanced Virtualization 8 are not affected by this issue, as they did not include the vulnerable code, which was introduced in a later version of the package (libvirt-v6.10.0).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8virt:rhel/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtNot affected
Red Hat Enterprise Linux 9libvirtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1962306libvirt: nodedev-list command may cause libvirt to crash on hosts with GRID driver installed

EPSS

Процентиль: 58%
0.00368
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
nvd
больше 4 лет назад

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
debian
больше 4 лет назад

A flaw was found in libvirt in the virConnectListAllNodeDevices API in ...

CVSS3: 6.5
github
больше 3 лет назад

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость API virConnectListAllNodeDevices библиотеки управления виртуализацией Libvirt при использовании драйвера GRID, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 58%
0.00368
Низкий

6.5 Medium

CVSS3