CVE-2013-6458: Race Condition
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6458?
CVE-2013-6458 has been classified with a moderate severity level due to its potential to cause a denial of service.
How do I fix CVE-2013-6458?
To resolve CVE-2013-6458, upgrade libvirt to version 1.2.1 or later.
Who is affected by CVE-2013-6458?
CVE-2013-6458 affects multiple versions of Red Hat Libvirt prior to 1.2.1.
What are the implications of CVE-2013-6458?
The implications of CVE-2013-6458 include the possibility of remote read-only attackers causing a denial of service.
What functions are affected by CVE-2013-6458?
CVE-2013-6458 impacts the virDomainBlockStats, virDomainGetBlockInf, qemuDomainBlockJobImpl, and virDomainGetBlockIoTune functions.