CVE-2013-7336
published 2014-05-07CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.33%
25.0th percentile
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.1.4-1 (bookworm) | libvirt 1.1.4-1 (bookworm) |
| opensuse | opensuse | — | — |
| redhat | libvirt | <= 1.1.2 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | libvirt | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | libvirt | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | libvirt | >= 0 < 1.1.4-1 | 1.1.4-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_ubuntu5.8MEDIUM
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-05-07·CVSS 5.8
CVE-2013-6456 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled symlinks when using the
LXC driver. An attacker could possibly use this issue to delete host
devices, create arbitrary nodes, and shutdown or power off the host.
(CVE-2013-6456)
Marian Krcmarik discovered that libvirt incorrectly handled seamless SPICE
migrations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2013-7336)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
libvirt: unprivileged user can crash libvirtd during spice migration
vendor_redhat·2013-09-19·CVSS 1.9
CVE-2013-7336 [LOW] libvirt: unprivileged user can crash libvirtd during spice migration
libvirt: unprivileged user can crash libvirtd during spice migration
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
Statement: Not vulnerable.
This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Linux 5 and 6 (since http://rhn.redhat.com/errata/RHBA-2013-1581.html, Red Hat Enterprise Linux 6.5 GA).
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-7336: libvirt - The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt befor...
vendor_debian·2013·CVSS 1.9
CVE-2013-7336 [LOW] CVE-2013-7336: libvirt - The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt befor...
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
Scope: local
bookworm: resolved (fixed in 1.1.4-1)
bullseye: resolved (fixed in 1.1.4-1)
forky: resolved (fixed in 1.1.4-1)
sid: resolved (fixed in 1.1.4-1)
trixie: resolved (fixed in 1.1.4-1)
GHSA
GHSA-xjqc-jjx2-53jr: The qemuMigrationWaitForSpice function in qemu/qemu_migration
ghsa_unreviewed·2022-05-14
CVE-2013-7336 [LOW] GHSA-xjqc-jjx2-53jr: The qemuMigrationWaitForSpice function in qemu/qemu_migration
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
OSV
CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration
osv·2014-05-07·CVSS 1.9
CVE-2013-7336 [LOW] CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7336 libvirt: unprivileged user can crash libvirtd during spice migration
bugzilla·2014-03-18·CVSS 1.9
CVE-2013-7336 [LOW] CVE-2013-7336 libvirt: unprivileged user can crash libvirtd during spice migration
CVE-2013-7336 libvirt: unprivileged user can crash libvirtd during spice migration
Description of the problem:
Domblkstat is possible even with read-only connection, so whenever
migration with spice is done and domblkstat gets called at the same time
as qemuMonitorGetSpiceMigrationStatus(), there is certain possibility that
the daemon crashes.
An unprivileged user able to issue commands to running libvirtd could use
this flaw to crash libvirtd and prevent more privileged clients from
working correctly.
Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=484cc321
Acknowledgements:
This issue was discovered by Marian Krcmarik of Red Hat.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Lin
Bugzilla
CVE-2013-7336 libvirtd crashes during established spice session migration. [rhel-6.5]
bugzilla·2013-09-19·CVSS 1.9
CVE-2013-7336 [LOW] CVE-2013-7336 libvirtd crashes during established spice session migration. [rhel-6.5]
CVE-2013-7336 libvirtd crashes during established spice session migration. [rhel-6.5]
Description of problem:
Source libvirtd crashes when performing migration on 6.5 host to 6.5 remote host with established spice session (spice client connected), The host is managed by RHEVM3.3. The crash does not happen when migration VM without spice session established, I am not able to reproduce that in different setup but my original setup has more complex setup (especially in networking) It uses separated display network for Spice traffic, separated network for VMs network interfaces. That all on bonded NICs. But I could reproduce even without display network.
I am attaching snip from source libvirtd where libvirtd crash is caught. As well as I attach core dump of libvirtd process.
Version-Releas
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=484cc321http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00004.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.openwall.com/lists/oss-security/2014/03/18/1http://www.openwall.com/lists/oss-security/2014/03/18/3https://bugzilla.redhat.com/show_bug.cgi?id=1077620http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=484cc321http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00004.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.openwall.com/lists/oss-security/2014/03/18/1http://www.openwall.com/lists/oss-security/2014/03/18/3https://bugzilla.redhat.com/show_bug.cgi?id=1077620
2014-05-07
Published