First published: Tue Jan 06 2015(Updated: )
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Libvirt | <=1.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8131 is considered to have a moderate severity due to its potential to cause denial of service.
To fix CVE-2014-8131, upgrade to libvirt version 1.2.11 or later.
CVE-2014-8131 is caused by improper handling of locks when domain access is restricted by ACL, leading to possible deadlocks.
Any system using libvirt versions prior to 1.2.11 is affected by CVE-2014-8131.
While CVE-2014-8131 primarily leads to denial of service, it does not directly cause data loss.