CVE-2013-6436
published 2014-01-07CVE-2013-6436: The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.35%
27.8th percentile
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.0-1 (bookworm) | libvirt 1.2.0-1 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.0-1 | 1.2.0-1 |
| redhat | libvirt | >= 0 < 1.2.0-1 | 1.2.0-1 |
| redhat | libvirt | >= 0 < 1.2.0-1 | 1.2.0-1 |
| redhat | libvirt | >= 0 < 1.2.0-1 | 1.2.0-1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 2.1
CVE-2013-6436 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Martin Kletzander discovered that libvirt incorrectly handled reading
memory tunables from LXC guests. A local user could possibly use this flaw
to cause libvirtd to crash, resulting in a denial of service. This issue
only affected Ubuntu 13.10. (CVE-2013-6436)
Dario Faggioli discovered that libvirt incorrectly handled the libxl
driver. A local user could possibly use this flaw to cause libvirtd to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)
It was discovered that libvirt contained multiple race conditions in block
device handling. A remote read-only user could use this flaw to cause
libvirtd to crash, resulting i
Red Hat
libvirt: crash in lxcDomainGetMemoryParameters
vendor_redhat·2013-12-20·CVSS 2.1
CVE-2013-6436 [LOW] libvirt: crash in lxcDomainGetMemoryParameters
libvirt: crash in lxcDomainGetMemoryParameters
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
Statement: Not vulnerable.
This issue did not affect the libvirt packages as shipped with Red Hat Enterprise Linux 5 and 6.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6436: libvirt - The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 thr...
vendor_debian·2013·CVSS 2.1
CVE-2013-6436 [LOW] CVE-2013-6436: libvirt - The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 thr...
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
Scope: local
bookworm: resolved (fixed in 1.2.0-1)
bullseye: resolved (fixed in 1.2.0-1)
forky: resolved (fixed in 1.2.0-1)
sid: resolved (fixed in 1.2.0-1)
trixie: resolved (fixed in 1.2.0-1)
GHSA
GHSA-3r95-9fm6-xqcf: The lxcDomainGetMemoryParameters method in lxc/lxc_driver
ghsa_unreviewed·2022-05-17
CVE-2013-6436 [LOW] GHSA-3r95-9fm6-xqcf: The lxcDomainGetMemoryParameters method in lxc/lxc_driver
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
OSV
CVE-2013-6436: The lxcDomainGetMemoryParameters method in lxc/lxc_driver
osv·2014-01-07·CVSS 2.1
CVE-2013-6436 [LOW] CVE-2013-6436: The lxcDomainGetMemoryParameters method in lxc/lxc_driver
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters [fedora-all]
bugzilla·2014-01-07·CVSS 2.1
CVE-2013-6436 [LOW] CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters [fedora-all]
CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters
bugzilla·2013-12-12·CVSS 2.1
CVE-2013-6436 [LOW] CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters
CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters
The lxcDomainGetMemoryParameters method in the LXC driver did not check whether the guest being accessed was running or not. When shutoff there will be no virCgroupPtr instance associated with the guest. Reading memory tunables involves calling methods with the virCgroupPtr object as a parameter. This will lead to a crash accessing a NULL pointer.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.
Acknowledgements:
This issue was discovered by Martin Kletzander of Red Hat.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the libvirt packages as shipped with Red Hat Enterprise Linux 5 and 6.
---
This issue was fixed upstream. Refer to:
https://www.redhat.com/arc
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f8c1cb90213508c4f32549023b0572ed774e48aahttp://lists.opensuse.org/opensuse-updates/2014-01/msg00004.htmlhttp://osvdb.org/101485http://secunia.com/advisories/56245http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://www.redhat.com/archives/libvir-list/2013-December/msg01170.htmlhttp://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f8c1cb90213508c4f32549023b0572ed774e48aahttp://lists.opensuse.org/opensuse-updates/2014-01/msg00004.htmlhttp://osvdb.org/101485http://secunia.com/advisories/56245http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://www.redhat.com/archives/libvir-list/2013-December/msg01170.html
2014-01-07
Published