CVE-2011-1486: Low severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
Description of problem: When several libvirtd threads are reporting errors at the same time, the errors can get mixed or corrupted, potentially leading to a libvirtd crash (DoS).
Upstream commit: https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html
Other sources
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1486?
CVE-2011-1486 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2011-1486?
To fix CVE-2011-1486, you should upgrade to libvirt version 0.8.9 or later.
Which versions of libvirt are affected by CVE-2011-1486?
CVE-2011-1486 affects all versions of libvirt up to and including 0.8.8.
What impact does CVE-2011-1486 have on libvirtd?
CVE-2011-1486 can lead to mixed or corrupted error reports and potential crashes of libvirtd.
Is CVE-2011-1486 remote exploit risk?
CVE-2011-1486 primarily poses a risk locally, but could potentially be exploited in specific network configurations.