Redhat

Libvirt

73 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Published 27.05.2021 19:15:07
  • Last modified 21.11.2024 04:55:53

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. De...

  • EPSS 0.37%
  • Published 24.05.2021 12:15:07
  • Last modified 21.11.2024 06:21:50

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client wit...

  • EPSS 0.07%
  • Published 03.12.2020 17:15:12
  • Last modified 21.11.2024 05:03:02

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest ...

  • EPSS 0.1%
  • Published 06.10.2020 14:15:12
  • Last modified 21.11.2024 05:18:18

A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, cl...

Exploit
  • EPSS 0.68%
  • Published 02.06.2020 13:15:10
  • Last modified 21.11.2024 04:55:53

A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created witho...

  • EPSS 0.8%
  • Published 28.04.2020 20:15:12
  • Last modified 21.11.2024 04:59:42

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing...

  • EPSS 0.36%
  • Published 19.03.2020 02:15:10
  • Last modified 21.11.2024 04:38:35

qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

  • EPSS 0.06%
  • Published 02.08.2019 13:15:12
  • Last modified 21.11.2024 04:18:33

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will ex...

  • EPSS 0.03%
  • Published 02.08.2019 13:15:12
  • Last modified 21.11.2024 04:18:33

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had alre...

  • EPSS 0.05%
  • Published 02.08.2019 13:15:12
  • Last modified 21.11.2024 04:18:33

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to pro...