CVE-2014-8136Ubuntu Linux vulnerability

CWE-26410 documents8 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 77.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19
Latest updateMay 14

Description

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages7 packages

Also affects: Ubuntu Linux 12.04, 14.04, 15.04, 15.10

🔴Vulnerability Details

4
GHSA
GHSA-24wj-qprw-6f7x: The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver2022-05-14
OSV
libvirt vulnerabilities2016-01-12
CVEList
CVE-2014-8136: The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver2014-12-19
OSV
CVE-2014-8136: The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver2014-12-19

📋Vendor Advisories

3
Ubuntu
libvirt vulnerabilities2016-01-12
Red Hat
libvirt: local denial of service in qemu/qemu_driver.c2014-12-17
Debian
CVE-2014-8136: libvirt - The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in q...2014

💬Community

2
Bugzilla
CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c2014-12-19
Bugzilla
CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c [fedora-all]2014-12-19
CVE-2014-8136 — Canonical Ubuntu Linux vulnerability | cvebase