[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1557 --- libvirt

ID: oval:org.secpod.oval:def:1700468Date: (C)2020-11-24   (M)2024-04-03
Class: PATCHFamily: unix




A flaw was found in the way the libvirtd daemon issued the "suspend" command to a QEMU guest-agent running inside a guest, where it holds a monitor job while issuing the "suspend" command to a guest-agent. A malicious guest-agent may use this flaw to block the libvirt daemon indefinitely, resulting in a denial of service. A NULL pointer dereference was found in the libvirt API responsible for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as network-based pools like gluster and RBD. Unprivileged users with a read-only connection could abuse this flaw to crash the libvirt daemon, resulting in a potential denial of service

Platform:
Amazon Linux 2
Product:
libvirt
Reference:
ALAS2-2020-1557
CVE-2019-20485
CVE-2020-10703
CVE    2
CVE-2019-20485
CVE-2020-10703

© SecPod Technologies