CVE-2014-0028: Medium severity redhat libvirt vulnerability

Published Jan 6, 2014
·
Updated

Eric Blake from Red Hat reports that ever since libvirt 1.1.1 added ACL domain:getattr filtering for commands like virConnectListAllDomains, we have had a latent problem that the use of virConnectDomainEventRegister() and virConnectDomainEventRegisterAny() can be used to learn about virDomainPtr objects that should have been inaccessible to the user. It is not a problem if you are not using ACLs; also, it is partially mitigated by the fact that any domain that does not trigger an event in the timeframe where the attacker maintains their event callback will not be leaked.

Once an attacker has learned about a domain by bypassing domain:getattr, they could perform other actions on the domain if there were not ACLs to filter those actions too, such as starting and stopping the domain.

Other sources

libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:searchdomains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.

MITRE

Affected Software

5 affected components
redhat libvirt=1.1.1
redhat libvirt=1.1.2
redhat libvirt=1.1.3
redhat libvirt=1.1.4
redhat libvirt=1.2.0

Event History

Jan 6, 2014
Data Sourced
via Red Hat·01:26 AM
DescriptionSeverityAffected Software
Jan 24, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-0028?

CVE-2014-0028 is classified as a moderate severity vulnerability.

2

How do I fix CVE-2014-0028?

To remediate CVE-2014-0028, you should upgrade to a fixed version of libvirt, such as 1.2.0 or later.

3

What versions of libvirt are affected by CVE-2014-0028?

CVE-2014-0028 affects libvirt versions 1.1.1 to 1.1.4.

4

What types of attacks can leverage CVE-2014-0028?

CVE-2014-0028 can potentially allow unauthorized access to sensitive domain information via event registration commands.

5

Who reported CVE-2014-0028?

CVE-2014-0028 was reported by Eric Blake from Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203