REDHAT-BUG-986383: High severity Red Hat libvirt vulnerability
A part of the returned monitor response was freed twice and caused crashes of the daemon when using guest agent cpu count retrieval.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd or, potentially, escalate their privilages to that of libvirtd process.
References: https://bugzilla.redhat.com/showbug.cgi?id=984821 https://www.redhat.com/archives/libvir-list/2013-July/msg01035.html
Acknowledgements:
This issue was discovered by Petr Krempa of Red Hat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-986383?
The severity of REDHAT-BUG-986383 is considered to be high due to the potential for crashes and privilege escalation.
How do I fix REDHAT-BUG-986383?
To fix REDHAT-BUG-986383, users should apply the latest security patches provided by Red Hat for the libvirt package.
Who is affected by REDHAT-BUG-986383?
Users running the affected versions of Red Hat libvirt are at risk of experiencing crashes or privilege escalation due to REDHAT-BUG-986383.
What are the potential impacts of REDHAT-BUG-986383?
The potential impacts of REDHAT-BUG-986383 include system crashes of the libvirt daemon and possible unauthorized privilege escalation.
Is there a workaround for REDHAT-BUG-986383?
Currently, there are no specific workarounds for REDHAT-BUG-986383 other than applying the recommended patches.