CVE-2011-1146: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
Description of problem: It has been found that several libvirt API calls (virNodeDeviceDettach, virNodeDeviceReset, virNodeDeviceReAttach, virDomainRevertToSnapshot, virDomainSnapshotDelete and virConnectDomainXMLToNative) did not honour read-only connection. Local attacker could use this flaw to crash the server (DoS) or possibly escalate his privileges.
Other sources
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1146?
CVE-2011-1146 has a medium severity rating due to the potential for local attackers to exploit the flaw.
How do I fix CVE-2011-1146?
To fix CVE-2011-1146, you should upgrade to a patched version of libvirt that addresses this vulnerability.
What are the affected versions of libvirt for CVE-2011-1146?
CVE-2011-1146 specifically affects libvirt version 0.8.8.
What types of attacks can CVE-2011-1146 enable?
CVE-2011-1146 could allow local attackers to perform unauthorized actions on the libvirt API.
Which libvirt API calls are impacted by CVE-2011-1146?
CVE-2011-1146 affects multiple libvirt API calls including virNodeDeviceDetach and virDomainSnapshotDelete.