qemu: job usage issue in several APIs leading to libvirtd crash
Published Jan 24, 2014
6.8
MEDIUMCVSS 2.0
EPSS 0.59%
Description
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Affected products
No data.
- ≤ 1.2.0
- 0.0.1
- 0.0.2
- 0.0.3
- 0.0.4
- 0.0.5
- 0.0.6
- 0.1.0
- 0.1.1
- 0.1.3
- 0.1.4
- 0.1.5
- 0.1.6
- 0.1.7
- 0.1.8
- 0.1.9
- 0.2.0
- 0.2.1
- 0.2.2
- 0.2.3
- 0.3.0
- 0.3.1
- 0.3.2
- 0.3.3
- 0.4.0
- 0.4.1
- 0.4.2
- 0.4.3
- 0.4.4
- 0.4.5
- 0.4.6
- 0.5.0
- 0.5.1
- 0.6.0
- 0.6.1
- 0.6.2
- 0.6.3
- 0.6.4
- 0.6.5
- 0.7.0
- 0.7.1
- 0.7.2
- 0.7.3
- 0.7.4
- 0.7.5
- 0.7.6
- 0.7.7
- 0.8.0
- 0.8.1
- 0.8.2
- 0.8.3
- 0.8.4
- 0.8.5
- 0.8.6
- 0.8.7
- 0.8.8
- 0.9.0
- 0.9.1
- 0.9.2
- 0.9.3
- 0.9.4
- 0.9.5
- 0.9.6
- 0.9.6.1
- 0.9.6.2
- 0.9.6.3
- 0.9.7
- 0.9.8
- 0.9.9
- 0.9.10
- 0.9.11
- 0.9.11.1
- 0.9.11.2
- 0.9.11.3
- 0.9.11.4
- 0.9.11.5
- 0.9.11.6
- 0.9.11.7
- 0.9.11.8
- 0.9.12
- 0.9.13
- 0.10.0
- 0.10.1
- 0.10.2
- 0.10.2.1
- 0.10.2.2
- 0.10.2.3
- 0.10.2.4
- 0.10.2.5
- 0.10.2.6
- 0.10.2.7
- 0.10.2.8
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.5.1
- 1.0.5.2
- 1.0.5.3
- 1.0.5.4
- 1.0.5.5
- 1.0.5.6
- 1.0.6
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
No data.
Red Hat Enterprise Linux 6
libvirt-0:0.10.2-29.el6_5.3
Fixed · RHSA-2014:0103
Red Hat Enterprise Linux 5
libvirt
Will not fix
Red Hat Enterprise Linux 7
libvirt
Not affected
Red Hat Storage 2
libvirt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libvirt-0:0.10.2-29.el6_5.3 | Fixed | RHSA-2014:0103 |
| Red Hat Enterprise Linux 5 | libvirt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libvirt | Not affected | n/a |
| Red Hat Storage 2 | libvirt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is now in Production 3 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (15)
- http://libvirt.org/news.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00060.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00062.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2014-0103.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/56186 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/56446 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/60895 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-04.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2014/dsa-2846 vendor-advisoryx_refsource_DEBIAN
- http://www.ubuntu.com/usn/USN-2093-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-6458 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1043069 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1048631 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-6458
- https://www.cve.org/CVERecord?id=CVE-2013-6458
Change history (0)
No recorded changes yet.