CVE-2014-7823
published 2014-11-13CVE-2014-7823: The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.91%
77.4th percentile
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.9-4 (bookworm) | libvirt 1.2.9-4 (bookworm) |
| redhat | libvirt | <= 1.2.10 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.9-4 | 1.2.9-4 |
| redhat | libvirt | >= 0 < 1.2.9-4 | 1.2.9-4 |
| redhat | libvirt | >= 0 < 1.2.9-4 | 1.2.9-4 |
| redhat | libvirt | >= 0 < 1.2.9-4 | 1.2.9-4 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.7 | 1.2.2-0ubuntu13.1.7 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49198 [MEDIUM] CWE-416 kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
In the Linux kernel, the following vulnerability has been resolved:
mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
Got crash when doing pressure test of mptcp:
dst_release: dst:ffffa06ce6e5c058 refcnt:-1
kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
BUG: unable to handle kernel paging request at ffffa06ce6e5c058
PGD 190a01067 P4D 190a01067 PUD 43fffb067 PMD 22e403063 PTE 8000000226e5c063
Oops: 0011 [#1] SMP PTI
CPU: 7 PID: 7823 Comm: kworker/7:0 Kdump: loaded Tainted: G E
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.2.1 04/01/2014
Call Trace:
? skb_release_head_state+0x68/0x100
? skb_release_all+0xe/0x30
? kfree_skb+0x32/0xa0
? mptcp
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-11-11·CVSS 5.0
CVE-2014-3657 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Pavel Hrdina discovered that libvirt incorrectly handled locking when
processing the virConnectListAllDomains command. An attacker could use this
issue to cause libvirtd to hang, resulting in a denial of service.
(CVE-2014-3657)
Eric Blake discovered that libvirt incorrectly handled permissions when
processing the qemuDomainFormatXML command. An attacker with read-only
privileges could possibly use this to gain access to certain information
from the domain xml file. (CVE-2014-7823)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: dumpxml: information leak with migratable flag
vendor_redhat·2014-11-05·CVSS 5.0
CVE-2014-7823 [MEDIUM] libvirt: dumpxml: information leak with migratable flag
libvirt: dumpxml: information leak with migratable flag
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
It was found that when the VIR_DOMAIN_XML_MIGRATABLE flag was used, the QEMU driver implementation of the virDomainGetXMLDesc() function could bypass the restrictions of the VIR_DOMAIN_XML_SECURE flag. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to leak certain limited information from the domain XML data.
Statement: This issue does not affect the versions of libvirt packages as shipped with
Red Hat Enterprise Linux 5.
This issue does affect the versions of libvirt packages as
Debian
CVE-2014-7823: libvirt - The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only use...
vendor_debian·2014·CVSS 5.0
CVE-2014-7823 [MEDIUM] CVE-2014-7823: libvirt - The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only use...
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Scope: local
bookworm: resolved (fixed in 1.2.9-4)
bullseye: resolved (fixed in 1.2.9-4)
forky: resolved (fixed in 1.2.9-4)
sid: resolved (fixed in 1.2.9-4)
trixie: resolved (fixed in 1.2.9-4)
GHSA
GHSA-v2x4-6r33-27c2: The virDomainGetXMLDesc API in Libvirt before 1
ghsa_unreviewed·2022-05-17
CVE-2014-7823 [MEDIUM] GHSA-v2x4-6r33-27c2: The virDomainGetXMLDesc API in Libvirt before 1
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
OSV
CVE-2014-7823: The virDomainGetXMLDesc API in Libvirt before 1
osv·2014-11-13·CVSS 5.0
CVE-2014-7823 [MEDIUM] CVE-2014-7823: The virDomainGetXMLDesc API in Libvirt before 1
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
OSV
libvirt vulnerabilities
osv·2014-11-11·CVSS 5.0
CVE-2014-3657 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
Pavel Hrdina discovered that libvirt incorrectly handled locking when
processing the virConnectListAllDomains command. An attacker could use this
issue to cause libvirtd to hang, resulting in a denial of service.
(CVE-2014-3657)
Eric Blake discovered that libvirt incorrectly handled permissions when
processing the qemuDomainFormatXML command. An attacker with read-only
privileges could possibly use this to gain access to certain information
from the domain xml file. (CVE-2014-7823)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-49198 kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
bugzilla·2025-02-26·CVSS 5.5
CVE-2022-49198 [MEDIUM] CVE-2022-49198 kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
CVE-2022-49198 kernel: mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
In the Linux kernel, the following vulnerability has been resolved:
mptcp: Fix crash due to tcp_tsorted_anchor was initialized before release skb
Got crash when doing pressure test of mptcp:
dst_release: dst:ffffa06ce6e5c058 refcnt:-1
kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
BUG: unable to handle kernel paging request at ffffa06ce6e5c058
PGD 190a01067 P4D 190a01067 PUD 43fffb067 PMD 22e403063 PTE 8000000226e5c063
Oops: 0011 [#1] SMP PTI
CPU: 7 PID: 7823 Comm: kworker/7:0 Kdump: loaded Tainted: G E
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.2.1 04/01/2014
Call Trace:
? skb_release_head_state+0x68/0x100
? skb_release_all+0xe/0x30
? kfree_skb
Bugzilla
CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag [fedora-all]
bugzilla·2014-11-05·CVSS 5.0
CVE-2014-7823 [MEDIUM] CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag [fedora-all]
CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag
bugzilla·2014-11-05·CVSS 5.0
CVE-2014-7823 [MEDIUM] CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag
CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag
In at least the qemu implementation of virDomainGetXMLDesc, the use
of the flag VIR_DOMAIN_XML_MIGRATABLE (which is usable from a
read-only connection) triggers the implicit use of
VIR_DOMAIN_XML_SECURE prior to calling qemuDomainFormatXML.
However, the use of VIR_DOMAIN_XML_SECURE is supposed to be restricted
to read-write clients only.
A remote attacker able to establish a read-only connection to libvirtd
could use this flaw to cause leak certain limited information from the
domain xml file.
Reference:
https://www.redhat.com/archives/libvir-list/2014-November/msg00114.html
Discussion:
Statement:
This issue does not affect the versions of libvirt packages as shipped with
Red Hat Enterprise Linux 5.
This issue doe
http://lists.opensuse.org/opensuse-updates/2014-11/msg00083.htmlhttp://secunia.com/advisories/60010http://secunia.com/advisories/60895http://secunia.com/advisories/62058http://secunia.com/advisories/62303http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0007.htmlhttp://www.ubuntu.com/usn/USN-2404-1http://lists.opensuse.org/opensuse-updates/2014-11/msg00083.htmlhttp://secunia.com/advisories/60010http://secunia.com/advisories/60895http://secunia.com/advisories/62058http://secunia.com/advisories/62303http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0007.htmlhttp://www.ubuntu.com/usn/USN-2404-1
2014-11-13
Published