CVE-2013-6457
published 2014-01-24CVE-2013-6457: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which…
PriorityP422medium5.2CVSS 2.0
AVAACLAuSCPIPAP
EPSS
0.66%
47.4th percentile
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
Affected
115 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.1-1 (bookworm) | libvirt 1.2.1-1 (bookworm) |
| redhat | libvirt | <= 1.2.0 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
osv5.2MEDIUM
vendor_debian5.2MEDIUM
vendor_redhat5.2MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw6x-8qwh-8q47: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver
ghsa_unreviewed·2022-05-17
CVE-2013-6457 [MEDIUM] GHSA-cw6x-8qwh-8q47: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
OSV
CVE-2013-6457: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver
osv·2014-01-24·CVSS 5.2
CVE-2013-6457 [MEDIUM] CVE-2013-6457: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 2.1
CVE-2013-6436 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Martin Kletzander discovered that libvirt incorrectly handled reading
memory tunables from LXC guests. A local user could possibly use this flaw
to cause libvirtd to crash, resulting in a denial of service. This issue
only affected Ubuntu 13.10. (CVE-2013-6436)
Dario Faggioli discovered that libvirt incorrectly handled the libxl
driver. A local user could possibly use this flaw to cause libvirtd to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)
It was discovered that libvirt contained multiple race conditions in block
device handling. A remote read-only user could use this flaw to cause
libvirtd to crash, resulting i
Red Hat
libvirt: avoid crashing if calling 'virsh numatune' on an inactive domain (libxl)
vendor_redhat·2013-12-20·CVSS 5.2
CVE-2013-6457 [MEDIUM] libvirt: avoid crashing if calling 'virsh numatune' on an inactive domain (libxl)
libvirt: avoid crashing if calling 'virsh numatune' on an inactive domain (libxl)
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Package: libvirt (Red Hat Storage 2.0) - Not affected
Package: libvirt (Red Hat Storage 2.1) - Not affected
Debian
CVE-2013-6457: libvirt - The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_drive...
vendor_debian·2013·CVSS 5.2
CVE-2013-6457 [MEDIUM] CVE-2013-6457: libvirt - The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_drive...
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
No detection rules found.
No public exploits indexed.
http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1048629https://www.redhat.com/archives/libvir-list/2013-December/msg01176.htmlhttps://www.redhat.com/archives/libvir-list/2013-December/msg01258.htmlhttp://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1048629https://www.redhat.com/archives/libvir-list/2013-December/msg01176.htmlhttps://www.redhat.com/archives/libvir-list/2013-December/msg01258.html
2014-01-24
Published