CVE-2013-6458
published 2014-01-24CVE-2013-6458: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in…
PriorityP421medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
0.59%
44.6th percentile
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Affected
115 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.1-1 (bookworm) | libvirt 1.2.1-1 (bookworm) |
| redhat | libvirt | <= 1.2.0 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hqh-qqff-45p6: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functio
ghsa_unreviewed·2022-05-17
CVE-2013-6458 [MEDIUM] CWE-362 GHSA-9hqh-qqff-45p6: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functio
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
OSV
CVE-2013-6458: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functio
osv·2014-01-24·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functio
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 2.1
CVE-2013-6436 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Martin Kletzander discovered that libvirt incorrectly handled reading
memory tunables from LXC guests. A local user could possibly use this flaw
to cause libvirtd to crash, resulting in a denial of service. This issue
only affected Ubuntu 13.10. (CVE-2013-6436)
Dario Faggioli discovered that libvirt incorrectly handled the libxl
driver. A local user could possibly use this flaw to cause libvirtd to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)
It was discovered that libvirt contained multiple race conditions in block
device handling. A remote read-only user could use this flaw to cause
libvirtd to crash, resulting i
Red Hat
qemu: job usage issue in several APIs leading to libvirtd crash
vendor_redhat·2013-12-13·CVSS 6.8
CVE-2013-6458 [MEDIUM] qemu: job usage issue in several APIs leading to libvirtd crash
qemu: job usage issue in several APIs leading to libvirtd crash
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: libvirt (Red Hat Enterprise Linux 5) - Will not fi
Debian
CVE-2013-6458: libvirt - Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockIn...
vendor_debian·2013·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458: libvirt - Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockIn...
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash [fedora-all]
bugzilla·2014-01-16·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash [fedora-all]
CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
Bugzilla
CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
bugzilla·2014-01-06·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
CVE-2013-6458 qemu: job usage issue in several APIs leading to libvirtd crash
A job usage issue in several APIs could allow an attacker who is able to establish a read-only connection to libvirtd to crash libvirtd.
Discussion:
Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=db86da5ca2109e4006c286a09b6c75bfe10676ad
https://bugzilla.redhat.com/show_bug.cgi?id=1043069#c15 notes "I found similar patterns in several other APIs and fixed them by the following commits: v1.2.0-233-gb799259, v1.2.0-234-gf93d2ca, v1.2.0-235-gff5f30b, v1.2.0-236-g3b56425."
---
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1054206]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2014:0103 https://rhn.redhat.com/errata/RHSA
Bugzilla
CVE-2013-6458 libvirtd crashes when swapping disks in qemu guest multiple times - qemuMonitorJSONGetBlockStatsInfo segfault [rhel-6.6]
bugzilla·2013-12-13·CVSS 6.8
CVE-2013-6458 [MEDIUM] CVE-2013-6458 libvirtd crashes when swapping disks in qemu guest multiple times - qemuMonitorJSONGetBlockStatsInfo segfault [rhel-6.6]
CVE-2013-6458 libvirtd crashes when swapping disks in qemu guest multiple times - qemuMonitorJSONGetBlockStatsInfo segfault [rhel-6.6]
Created attachment 836510
contains 4 files
Description of problem:
We are facing a common issue here where libvirtd constantly crashes after attaching and detaching multiple times a disk on a qemu guest (windows 7 or linux).
The problem arises in our production OpenStack cluster. We have scripts in place to do continuous tests for EBS attachments of running instances.
The problem seems to happen qemuDomainBlockStats() of qemu/qemu_driver.c where the disk parameter (dev_name) to qemuMonitorJSONGetBlockStatsInfo becomes NULL.
I will let you take a deeper look at the segfault information for analysis.
I have attached 2 separate GDB log session with back
http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0103.htmlhttp://secunia.com/advisories/56186http://secunia.com/advisories/56446http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.debian.org/security/2014/dsa-2846http://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1043069http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0103.htmlhttp://secunia.com/advisories/56186http://secunia.com/advisories/56446http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.debian.org/security/2014/dsa-2846http://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1043069
2014-01-24
Published