CVE-2024-8235
- EPSS 0.11%
- Veröffentlicht 30.08.2024 17:15:15
- Zuletzt bearbeitet 21.11.2024 09:52:55
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer de...
CVE-2024-2496
- EPSS 0.03%
- Veröffentlicht 18.03.2024 13:15:08
- Zuletzt bearbeitet 09.04.2025 15:36:43
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. Th...
CVE-2023-3750
- EPSS 0.12%
- Veröffentlicht 24.07.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 08:17:58
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow c...
CVE-2023-2700
- EPSS 0.03%
- Veröffentlicht 15.05.2023 22:15:12
- Zuletzt bearbeitet 28.01.2025 17:15:14
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autopt...
CVE-2021-3975
- EPSS 0.26%
- Veröffentlicht 23.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:23:17
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAl...
CVE-2022-0897
- EPSS 0.05%
- Veröffentlicht 25.03.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:37
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrentl...
CVE-2021-4147
- EPSS 0.06%
- Veröffentlicht 25.03.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:00
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
CVE-2021-3631
- EPSS 0.04%
- Veröffentlicht 02.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:01
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat ...
CVE-2021-3667
- EPSS 0.28%
- Veröffentlicht 02.03.2022 23:15:08
- Zuletzt bearbeitet 10.02.2025 13:10:12
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients co...
CVE-2020-14301
- EPSS 0.26%
- Veröffentlicht 27.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:02:57
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive inform...