Where
-Infinity
0
Severity
4.6
Race Condition
AV:L/AC:L/Au:N/C:P/I:P/A:P

libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

First published (updated )
Severity
4

It has been found that sending RPC message with an event as the RPC number, or RPC number that falls into gap in the RPC dispatch table, can lead to libvirtd accessing memory at page zero. A remote attacker could use this flaw to crash libvirtd (DoS).

Proposed upstream fix: https://www.redhat.com/archives/libvir-list/2012-September/msg00843.html

First published (updated )
Severity
4

If users haven't configured guest agent then qemuAgentCommand() will dereference a NULL 'mon' pointer.

A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.

References: https://bugzilla.redhat.com/showbug.cgi?id=984821 https://www.redhat.com/archives/libvir-list/2013-July/msg00992.html

Acknowledgements:

This issue was discovered by Alex Jia of Red Hat.

First published (updated )
Severity
7

A part of the returned monitor response was freed twice and caused crashes of the daemon when using guest agent cpu count retrieval.

A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd or, potentially, escalate their privilages to that of libvirtd process.

References: https://bugzilla.redhat.com/showbug.cgi?id=984821 https://www.redhat.com/archives/libvir-list/2013-July/msg01035.html

Acknowledgements:

This issue was discovered by Petr Krempa of Red Hat.

First published (updated )
Severity
4

It has been found that sending crafted RPC command with nparams set to 0 can lead to libvirtd accessing random memory, possibly leading to crash. A remote attacker could use this flaw to crash libvirtd (DoS).

Upstream proposed fix: https://www.redhat.com/archives/libvir-list/2012-July/msg01650.html

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203