CVE-2020-10701: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
A bug was reported internally about a bug in libvirt allowing a user on a read-only to change the response timeout for all guest agent messages. Changing this timeout can potentially cause some commands to fail.
Other sources
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10701?
CVE-2020-10701 is a vulnerability found in the libvirt API that allows read-only connections to adjust the QEMU agent response timeout.
How severe is CVE-2020-10701?
CVE-2020-10701 has a severity rating of 6.5 out of 10, which is considered medium.
What is the affected software for CVE-2020-10701?
The affected software for CVE-2020-10701 is libvirt version up to 6.2.0.
How can I fix CVE-2020-10701?
To fix CVE-2020-10701, update libvirt to version 6.2.0 or above.
Where can I find more information about CVE-2020-10701?
You can find more information about CVE-2020-10701 in the following references: [link1], [link2], [link3].