REDHAT-BUG-1015259: High severity oracle libvirt vulnerability
A flaw was found in libvirt where libvirtd could crash due to how XML was parsed [1]. With the introduction of ACL permissions in libvirt 1.1.0, this flaw could be manipulated to allow a remote user with connect:read privileges to elevate them to the more permissive domain:write privilege.
This vulnerability was introduced in libvirt 1.1.0.
[1] https://bugzilla.redhat.com/showbug.cgi?id=1012196;
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1015259?
The severity of REDHAT-BUG-1015259 is critical due to the potential for privilege escalation.
How do I fix REDHAT-BUG-1015259?
To fix REDHAT-BUG-1015259, update to the latest version of libvirt that addresses this vulnerability.
Who is affected by REDHAT-BUG-1015259?
Users of libvirt version 1.1.0 and above with connect:read privileges are affected by REDHAT-BUG-1015259.
What kind of attack is possible with REDHAT-BUG-1015259?
An attacker could exploit REDHAT-BUG-1015259 to escalate their privileges from connect:read to domain:write.
When was REDHAT-BUG-1015259 discovered?
REDAHT-BUG-1015259 was discovered following the introduction of ACL permissions in libvirt 1.1.0.