REDHAT-BUG-2270115: Medium severity oracle libvirt vulnerability
A flaw was found in the RPC library APIs of libvirt. The RPC server de-serialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the gnew0 function results in a crash due to the negative length being treated as a huge positive number. A local unprivileged user could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2270115?
The severity of REDHAT-BUG-2270115 is classified as high due to the potential for crashing the application.
How do I fix REDHAT-BUG-2270115?
To fix REDHAT-BUG-2270115, you should update to the latest version of libvirt that incorporates the necessary security patches.
What systems are affected by REDHAT-BUG-2270115?
REDHAT-BUG-2270115 affects systems that utilize the libvirt RPC library APIs.
Is there a workaround for REDHAT-BUG-2270115?
A workaround for REDHAT-BUG-2270115 involves avoiding the use of affected RPC API calls until a patch is applied.
What version of libvirt should I use to avoid REDHAT-BUG-2270115?
You should use the latest stable version of libvirt that has addressed the vulnerabilities mentioned in REDHAT-BUG-2270115.