CVE-2020-12430: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
A libvirt flaw affecting the domstats command was reported internally. This bug may allow a user on a read-only connection to cause a memory leak in domstats, resulting in a potential denial of service.
Reference: https://bugzilla.redhat.com/showbug.cgi?id=1804548
Upstream fix: https://libvirt.org/git/?p=libvirt.git;a=commit;h=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581
Other sources
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemudriver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
— Ubuntu
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-12430?
CVE-2020-12430 is a vulnerability found in libvirt, a library for managing virtualization technologies, before version 6.1.0.
How does CVE-2020-12430 affect my system?
CVE-2020-12430 can lead to a memory leak in the virDomainListGetStats libvirt API, potentially allowing unprivileged users to exhaust system memory resources.
What is the severity of CVE-2020-12430?
The severity of CVE-2020-12430 is medium, with a CVSS score of 6.5.
Which versions of libvirt are affected by CVE-2020-12430?
Versions of libvirt before 6.1.0 are affected by CVE-2020-12430.
How can I fix CVE-2020-12430?
Update libvirt to version 6.1.0 or later to fix CVE-2020-12430.