CVE-2014-3657
published 2014-10-06CVE-2014-3657: The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.79%
84.9th percentile
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.9-1 (bookworm) | libvirt 1.2.9-1 (bookworm) |
| libvirt | libvirt | <= 1.2.8 | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.9-1 | 1.2.9-1 |
| redhat | libvirt | >= 0 < 1.2.9-1 | 1.2.9-1 |
| redhat | libvirt | >= 0 < 1.2.9-1 | 1.2.9-1 |
| redhat | libvirt | >= 0 < 1.2.9-1 | 1.2.9-1 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.7 | 1.2.2-0ubuntu13.1.7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 5.0
CVE-2014-3657 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Pavel Hrdina discovered that libvirt incorrectly handled locking when
processing the virConnectListAllDomains command. An attacker could use this
issue to cause libvirtd to hang, resulting in a denial of service.
(CVE-2014-3657)
Eric Blake discovered that libvirt incorrectly handled permissions when
processing the qemuDomainFormatXML command. An attacker with read-only
privileges could possibly use this to gain access to certain information
from the domain xml file. (CVE-2014-7823)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: domain_conf: domain deadlock DoS
vendor_redhat·2014-10-01·CVSS 5.0
CVE-2014-3657 [MEDIUM] CWE-20 libvirt: domain_conf: domain deadlock DoS
libvirt: domain_conf: domain deadlock DoS
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
A denial of service flaw was found in the way libvirt's virConnectListAllDomains() function computed the number of used domains. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to make any domain operations within libvirt unresponsive.
Statement: This issue does not affect the versions of libvirt packages as shipped with
Red Hat Enterprise Linux 5.
This issue does affect the versions of libvirt packages as shipped with R
Debian
CVE-2014-3657: libvirt - The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9...
vendor_debian·2014·CVSS 5.0
CVE-2014-3657 [MEDIUM] CVE-2014-3657: libvirt - The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9...
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.2.9-1)
GHSA
GHSA-543q-9rm2-x5f3: The virDomainListPopulate function in conf/domain_conf
ghsa_unreviewed·2022-05-17
CVE-2014-3657 [MEDIUM] GHSA-543q-9rm2-x5f3: The virDomainListPopulate function in conf/domain_conf
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
OSV
libvirt vulnerabilities
osv·2014-11-11·CVSS 5.0
CVE-2014-3657 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
Pavel Hrdina discovered that libvirt incorrectly handled locking when
processing the virConnectListAllDomains command. An attacker could use this
issue to cause libvirtd to hang, resulting in a denial of service.
(CVE-2014-3657)
Eric Blake discovered that libvirt incorrectly handled permissions when
processing the qemuDomainFormatXML command. An attacker with read-only
privileges could possibly use this to gain access to certain information
from the domain xml file. (CVE-2014-7823)
OSV
CVE-2014-3657: The virDomainListPopulate function in conf/domain_conf
osv·2014-10-06·CVSS 5.0
CVE-2014-3657 [MEDIUM] CVE-2014-3657: The virDomainListPopulate function in conf/domain_conf
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS [fedora-all]
bugzilla·2014-11-05·CVSS 5.0
CVE-2014-3657 [MEDIUM] CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS [fedora-all]
CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS
bugzilla·2014-09-23·CVSS 5.0
CVE-2014-3657 [MEDIUM] CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS
CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS
If public api virConnectListAllDomains() with second parameter
set to NULL to get only the number of domains is used, it will
lock out all other operations with domains.
A remote attacker able to establish a read-only connection to
libvirtd could use this flaw to cause libvirtd denial of
service.
Introduced by:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=2c680804
Discussion:
Statement:
This issue does not affect the versions of libvirt packages as shipped with
Red Hat Enterprise Linux 5.
This issue does affect the versions of libvirt packages as shipped with Red Hat
Enterprise Linux 6 and 7. Future updates may address this issue in the
respective Red Hat Enterprise Linux releases.
---
IssueDescription:
A denial of servi
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=fc22b2e74890873848b43fffae43025d22053669http://lists.opensuse.org/opensuse-updates/2014-10/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1352.htmlhttp://secunia.com/advisories/60291http://secunia.com/advisories/62303http://security.libvirt.org/2014/0005.htmlhttp://www.ubuntu.com/usn/USN-2404-1http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=fc22b2e74890873848b43fffae43025d22053669http://lists.opensuse.org/opensuse-updates/2014-10/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1352.htmlhttp://secunia.com/advisories/60291http://secunia.com/advisories/62303http://security.libvirt.org/2014/0005.htmlhttp://www.ubuntu.com/usn/USN-2404-1
2014-10-06
Published