CVE-2015-5247
published 2016-04-14CVE-2015-5247: The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service…
PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.37%
68.8th percentile
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libvirt | < libvirt 1.2.20-1 (bookworm) | libvirt 1.2.20-1 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.20-1 | 1.2.20-1 |
| redhat | libvirt | >= 0 < 1.2.20-1 | 1.2.20-1 |
| redhat | libvirt | >= 0 < 1.2.20-1 | 1.2.20-1 |
| redhat | libvirt | >= 0 < 1.2.20-1 | 1.2.20-1 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.16 | 1.2.2-0ubuntu13.1.16 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2016-01-12·CVSS 5.9
CVE-2011-4600 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affe
Red Hat
libvirt: denial of service when volume creation fails on NFS pool
vendor_redhat·2015-09-03·CVSS 6.5
CVE-2015-5247 [MEDIUM] libvirt: denial of service when volume creation fails on NFS pool
libvirt: denial of service when volume creation fails on NFS pool
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-5247: libvirt - The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote au...
vendor_debian·2015·CVSS 6.5
CVE-2015-5247 [MEDIUM] CVE-2015-5247: libvirt - The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote au...
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
Scope: local
bookworm: resolved (fixed in 1.2.20-1)
bullseye: resolved (fixed in 1.2.20-1)
forky: resolved (fixed in 1.2.20-1)
sid: resolved (fixed in 1.2.20-1)
trixie: resolved (fixed in 1.2.20-1)
GHSA
GHSA-xq4r-xr6r-76qw: The virStorageVolCreateXML API in libvirt 1
ghsa_unreviewed·2022-05-17
CVE-2015-5247 [MEDIUM] CWE-284 GHSA-xq4r-xr6r-76qw: The virStorageVolCreateXML API in libvirt 1
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
OSV
CVE-2015-5247: The virStorageVolCreateXML API in libvirt 1
osv·2016-04-14·CVSS 6.5
CVE-2015-5247 [MEDIUM] CVE-2015-5247: The virStorageVolCreateXML API in libvirt 1
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
OSV
libvirt vulnerabilities
osv·2016-01-12·CVSS 5.9
CVE-2011-4600 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affected Ubuntu 14.04
LTS. (CVE-2015-0236)
Han Han discovered that
No detection rules found.
No public exploits indexed.
2016-04-14
Published