libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
Published Mar 19, 2020
5.8
MEDIUMCVSS 3.1
EPSS 0.81%
Description
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
Affected products
No data.
Configuration 2
- 8.0
- 9.0
- 10.0
Configuration 3
- 31
No data.
Advanced Virtualization for RHEL 8.2.0
virt-devel:8.2-8020020200414225921.6a468ee4
Fixed · RHBA-2020:2017
Advanced Virtualization for RHEL 8.2.0
virt:8.2-8020020200414225921.6a468ee4
Fixed · RHBA-2020:2017
Red Hat Enterprise Linux 7
libvirt-0:4.5.0-36.el7
Fixed · RHSA-2020:4000
Red Hat Enterprise Linux 8
virt-devel:rhel-8030020200909014558.30b713e6
Fixed · RHSA-2020:4676
Red Hat Enterprise Linux 8
virt:rhel-8030020200909014558.30b713e6
Fixed · RHSA-2020:4676
Red Hat Enterprise Linux 5
libvirt
Out of support scope
Red Hat Enterprise Linux 6
libvirt
Out of support scope
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.1/libvirt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Advanced Virtualization for RHEL 8.2.0 | virt-devel:8.2-8020020200414225921.6a468ee4 | Fixed | RHBA-2020:2017 |
| Advanced Virtualization for RHEL 8.2.0 | virt:8.2-8020020200414225921.6a468ee4 | Fixed | RHBA-2020:2017 |
| Red Hat Enterprise Linux 7 | libvirt-0:4.5.0-36.el7 | Fixed | RHSA-2020:4000 |
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8030020200909014558.30b713e6 | Fixed | RHSA-2020:4676 |
| Red Hat Enterprise Linux 8 | virt:rhel-8030020200909014558.30b713e6 | Fixed | RHSA-2020:4676 |
| Red Hat Enterprise Linux 5 | libvirt | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libvirt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/libvirt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of the libvirt package as shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt updates for Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue. Red Hat Enterprise Linux version 5 and 6 are in Maintenance Support 2 Phase of the life cycle. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates of the Red Hat Enterprise Linux version 5 and 6. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (10)
- https://access.redhat.com/security/cve/CVE-2019-20485 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953078 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1809740 x_refsource_MISCIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11029 Advisory
- https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=a663a860819287e041c3de672aad1d8543098ecc x_refsource_CONFIRM
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-20485
- https://security-tracker.debian.org/tracker/CVE-2019-20485 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20485
- https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1730509.html x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-20485 | Vendor Advisory | |
| https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953078 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1809740 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11029 | Advisory | |
| https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=a663a860819287e041c3de672aad1d8543098ecc | x_refsource_CONFIRM | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20485 | ||
| https://security-tracker.debian.org/tracker/CVE-2019-20485 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-20485 | ||
| https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1730509.html | x_refsource_MISC |
Change history (0)
No recorded changes yet.