CVE-2011-1486
published 2011-05-31CVE-2011-1486: libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing…
PriorityP410low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
1.20%
64.7th percentile
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.9.0-1 (bookworm) | libvirt 0.9.0-1 (bookworm) |
| redhat | libvirt | <= 0.8.8 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_ubuntu4.4MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wmfm-p2jq-55wv: libvirtd in libvirt before 0
ghsa_unreviewed·2022-05-17
CVE-2011-1486 [LOW] GHSA-wmfm-p2jq-55wv: libvirtd in libvirt before 0
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
OSV
CVE-2011-1486: libvirtd in libvirt before 0
osv·2011-05-31·CVSS 3.3
CVE-2011-1486 [LOW] CVE-2011-1486: libvirtd in libvirt before 0
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2011-06-16·CVSS 4.4
CVE-2011-1486 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Libvirt could be made to crash or read arbitrary files on the host.
It was discovered that libvirt did not use thread-safe error reporting. A
remote attacker could exploit this to cause a denial of service via
application crash. (CVE-2011-1486)
Eric Blake discovered that libvirt had an off-by-one error which could
be used to reopen disk probing and bypass the fix for CVE-2010-2238. A
privileged attacker in the guest could exploit this to read arbitrary files
on the host. This issue only affected Ubuntu 11.04. By default, guests are
confined by an AppArmor profile which provided partial protection against
this flaw. (CVE-2011-2178)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvirt: error reporting in libvirtd is not thread safe
vendor_redhat·2011-03-23·CVSS 3.3
CVE-2011-1486 [LOW] libvirt: error reporting in libvirtd is not thread safe
libvirt: error reporting in libvirtd is not thread safe
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Package: libvirt (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2011-1486: libvirt - libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which...
vendor_debian·2011·CVSS 3.3
CVE-2011-1486 [LOW] CVE-2011-1486: libvirt - libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which...
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Scope: local
bookworm: resolved (fixed in 0.9.0-1)
bullseye: resolved (fixed in 0.9.0-1)
forky: resolved (fixed in 0.9.0-1)
sid: resolved (fixed in 0.9.0-1)
trixie: resolved (fixed in 0.9.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe
bugzilla·2011-04-04·CVSS 3.3
CVE-2011-1486 [LOW] CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe
CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe
Description of problem:
When several libvirtd threads are reporting errors at the same time,
the errors can get mixed or corrupted, potentially leading to a
libvirtd crash (DoS).
Upstream commit:
https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html
Discussion:
This was assigned the CVE name CVE-2011-1486:
http://permalink.gmane.org/gmane.comp.security.oss.general/4749
---
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 693457]
---
Verified with libvirt-0.8.1-27.el6_0.6 :
# ./concurrent_errors $(pidof libvirtd) kvm-rhel6-x86_64
Attempting to connect to hypervisor
Connected to hypervisor at "qemu:///system"
Starting 5 threads
Watching libvirtd PID 4548
^C
#
---
This issue
Bugzilla
CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe [fedora-all]
bugzilla·2011-04-04·CVSS 3.3
CVE-2011-1486 [LOW] CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe [fedora-all]
CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=693391
Please note: this issue affects
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f44bfb7fb978c9313ce050a1c4149bf04aa0a670http://secunia.com/advisories/44459http://securitytracker.com/id?1025477http://support.avaya.com/css/P8/documents/100134583http://www.debian.org/security/2011/dsa-2280http://www.redhat.com/support/errata/RHSA-2011-0478.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0479.htmlhttp://www.securityfocus.com/bid/47148http://www.ubuntu.com/usn/USN-1152-1https://bugzilla.redhat.com/show_bug.cgi?id=693391https://www.redhat.com/archives/libvir-list/2011-March/msg01087.htmlhttp://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f44bfb7fb978c9313ce050a1c4149bf04aa0a670http://secunia.com/advisories/44459http://securitytracker.com/id?1025477http://support.avaya.com/css/P8/documents/100134583http://www.debian.org/security/2011/dsa-2280http://www.redhat.com/support/errata/RHSA-2011-0478.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0479.htmlhttp://www.securityfocus.com/bid/47148http://www.ubuntu.com/usn/USN-1152-1https://bugzilla.redhat.com/show_bug.cgi?id=693391https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html
2011-05-31
Published