CVE-2015-5247: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
Published Apr 14, 2016
·Updated
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a rootsquash NFS pool.
Affected Software
10 affected components
redhat libvirt=1.2.14
redhat libvirt=1.2.15
redhat libvirt=1.2.16
redhat libvirt=1.2.17
redhat libvirt=1.2.18
redhat libvirt=1.2.19
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
Event History
Apr 14, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5247?
CVE-2015-5247 is classified as a denial of service vulnerability.
2
How does CVE-2015-5247 affect systems?
CVE-2015-5247 allows remote authenticated users to crash the libvirtd service.
3
Which versions of libvirt are affected by CVE-2015-5247?
CVE-2015-5247 affects libvirt versions 1.2.14 through 1.2.19.
4
How do I fix CVE-2015-5247?
To fix CVE-2015-5247, upgrade libvirt to a version after 1.2.19.
5
Can CVE-2015-5247 be exploited remotely?
Yes, CVE-2015-5247 can be exploited by remote authenticated users.