CVE-2014-8131: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8131?
CVE-2014-8131 is considered to have a moderate severity due to its potential to cause denial of service.
How do I fix CVE-2014-8131?
To fix CVE-2014-8131, upgrade to libvirt version 1.2.11 or later.
What causes CVE-2014-8131?
CVE-2014-8131 is caused by improper handling of locks when domain access is restricted by ACL, leading to possible deadlocks.
Who is affected by CVE-2014-8131?
Any system using libvirt versions prior to 1.2.11 is affected by CVE-2014-8131.
Can CVE-2014-8131 lead to data loss?
While CVE-2014-8131 primarily leads to denial of service, it does not directly cause data loss.