libvirt: memory leak in domstats may allow read-only user to perform DoS attack
Published Apr 28, 2020
6.5
MEDIUMCVSS 3.1
EPSS 2.27%
Description
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
Affected products
No data.
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux 5
libvirt
Not affected
Red Hat Enterprise Linux 6
libvirt
Not affected
Red Hat Enterprise Linux 7
libvirt
Not affected
Red Hat Enterprise Linux 8
virt:rhel/libvirt
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.1/libvirt
Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/libvirt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | virt:rhel/libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/libvirt | Will not fix | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libvirt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Versions of `libvirt` as shipped with Red Hat Enterprise Linux are marked as "notaffected" because they do not include the vulnerable code, which was introduced in a later version of the package. Specifically, the affected function `qemuDomainGetStatsIOThread()` was introduced in `libvirt` upstream version 4.10.0. RHEL Advanced Virtualization is affected by this flaw as it ships a more recent version of the package.
References (10)
- https://access.redhat.com/security/cve/CVE-2020-12430 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1804548 Issue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1828190 Issue TrackingPatchVendor Advisory
- https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-12430
- https://security.netapp.com/advisory/ntap-20200518-0003/
- https://usn.ubuntu.com/4371-1/ vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-12430
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-12430 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1804548 | Issue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1828190 | Issue TrackingPatchVendor Advisory | |
| https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581 | ||
| https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html | mailing-list | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-12430 | ||
| https://security.netapp.com/advisory/ntap-20200518-0003/ | ||
| https://usn.ubuntu.com/4371-1/ | vendor-advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-12430 |
Change history (0)
No recorded changes yet.