CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case w...Show more |
2Debian Redhat3Debian Linux Enterprise LinuxLibvirtApr 9, 2025 Mar 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virCo...Show more |
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another th...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraLibvirtJan 28, 2025 May 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array withi...Show more |
5Canonical DebianFedoraproject+2 more14Codeready Linux Builder Debian LinuxEnterprise Linux+11 moreNov 21, 2024 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be tr...Show more |
2Netapp Redhat2Libvirt Ontap Select Deploy Administration UtilityNov 21, 2024 Mar 25, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop a...Show more |
3Fedoraproject NetappRedhat3Fedora LibvirtOntap Select Deploy Administration UtilityNov 21, 2024 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. |
3Debian NetappRedhat4Debian Linux Enterprise LinuxLibvirt+1 moreFeb 10, 2025 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL...Show more |
2Netapp Redhat4Enterprise Linux LibvirtOntap Select Deploy Administration Utility+1 moreNov 21, 2024 Mar 2, 2022 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt co...Show more |
2Netapp Redhat13Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+10 moreNov 21, 2024 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to acces...Show more |
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to...Show more |
2Netapp Redhat2Libvirt Ontap Select Deploy Administration UtilityNov 21, 2024 May 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used...Show more |
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This...Show more |
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access co...Show more |
A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affec...Show more |
1Redhat 2Enterprise Linux LibvirtNov 21, 2024 Apr 28, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving d...Show more |
3Debian FedoraprojectRedhat3Debian Linux FedoraLibvirtNov 21, 2024 Mar 19, 2020 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage). |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain....Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt wi...Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state fil...Show more |