CVE-2020-10703: Null Pointer Dereference
A flaw was found in libvirt. A pool created without a target path may lead to segmentation fault and denial of service. This issue may be triggered by a read only user.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1790725
Other sources
A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as network-based pools like gluster and RBD. Unprivileged users with a read-only connection could abuse this flaw to crash the libvirt daemon, resulting in a potential denial of service.
— Ubuntu
A NULL pointer dereference was found in the libvirt API responsible for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as network-based pools like gluster and RBD. Unprivileged users with a read-only connection could abuse this flaw to crash the libvirt daemon, resulting in a potential denial of service.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10703?
CVE-2020-10703 is a vulnerability that involves a NULL pointer dereference in the libvirt API responsible for fetching a storage pool based on its target path.
How severe is CVE-2020-10703?
CVE-2020-10703 has a severity rating of 6.5 (medium).
Which software is affected by CVE-2020-10703?
This vulnerability affects libvirt versions up to and including 6.0.0 on Red Hat, Debian, and Ubuntu systems.
How can I fix CVE-2020-10703?
To fix CVE-2020-10703, you should update libvirt to version 6.0.0 or higher.
Where can I find more information about CVE-2020-10703?
You can find more information about CVE-2020-10703 on the Red Hat Bugzilla and libvirt websites.