REDHAT-BUG-986386: Medium severity Red Hat libvirt vulnerability
If users haven't configured guest agent then qemuAgentCommand() will dereference a NULL 'mon' pointer.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.
References: https://bugzilla.redhat.com/showbug.cgi?id=984821 https://www.redhat.com/archives/libvir-list/2013-July/msg00992.html
Acknowledgements:
This issue was discovered by Alex Jia of Red Hat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-986386?
The severity of REDHAT-BUG-986386 is considered moderate, as it allows a remote user to crash the libvirtd service.
How do I fix REDHAT-BUG-986386?
To fix REDHAT-BUG-986386, ensure that the guest agent is properly configured to avoid NULL pointer dereferencing.
Who is affected by REDHAT-BUG-986386?
Users of Red Hat libvirt without a configured guest agent are affected by REDHAT-BUG-986386.
What actions can an attacker take with REDHAT-BUG-986386?
An attacker could issue commands to the libvirt daemon and potentially crash libvirtd due to this vulnerability.
Is there a workaround for REDHAT-BUG-986386?
Currently, the best workaround for REDHAT-BUG-986386 is to disable remote command access to the libvirt daemon until it is properly patched.