First published: Mon Apr 27 2020(Updated: )
A libvirt flaw affecting the domstats command was reported internally. This bug may allow a user on a read-only connection to cause a memory leak in domstats, resulting in a potential denial of service. Reference: <a class="bz_bug_link bz_secure " title="" href="show_bug.cgi?id=1804548">https://bugzilla.redhat.com/show_bug.cgi?id=1804548</a> Upstream fix: <a href="https://libvirt.org/git/?p=libvirt.git;a=commit;h=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581">https://libvirt.org/git/?p=libvirt.git;a=commit;h=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581</a>
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | >=4.10.0<6.1.0 | |
Redhat Enterprise Linux | =8.0 | |
redhat/libvirt | <6.1.0 | 6.1.0 |
ubuntu/libvirt | <5.4.0-0ubuntu5.4 | 5.4.0-0ubuntu5.4 |
ubuntu/libvirt | <6.0.0-0ubuntu6 | 6.0.0-0ubuntu6 |
debian/libvirt | 7.0.0-3+deb11u2 9.0.0-4 10.6.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12430 is a vulnerability found in libvirt, a library for managing virtualization technologies, before version 6.1.0.
CVE-2020-12430 can lead to a memory leak in the virDomainListGetStats libvirt API, potentially allowing unprivileged users to exhaust system memory resources.
The severity of CVE-2020-12430 is medium, with a CVSS score of 6.5.
Versions of libvirt before 6.1.0 are affected by CVE-2020-12430.
Update libvirt to version 6.1.0 or later to fix CVE-2020-12430.