CVE-2017-2635
published 2018-08-22CVE-2017-2635: A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to…
PriorityP429medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.53%
71.9th percentile
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 3.0.0-3 (bookworm) | libvirt 3.0.0-3 (bookworm) |
| redhat | libvirt | >= 0 < 3.0.0-3 | 3.0.0-3 |
| redhat | libvirt | >= 0 < 3.0.0-3 | 3.0.0-3 |
| redhat | libvirt | >= 0 < 3.0.0-3 | 3.0.0-3 |
| redhat | libvirt | >= 0 < 3.0.0-3 | 3.0.0-3 |
| redhat | libvirt | 2.5.0 – 3.0.0 | — |
| the_libvirt_project | libvirt | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wgv-m454-22mq: A NULL pointer deference flaw was found in the way libvirt from 2
ghsa_unreviewed·2022-05-13
CVE-2017-2635 [MEDIUM] CWE-476 GHSA-6wgv-m454-22mq: A NULL pointer deference flaw was found in the way libvirt from 2
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
OSV
CVE-2017-2635: A NULL pointer deference flaw was found in the way libvirt from 2
osv·2018-08-22·CVSS 6.5
CVE-2017-2635 [MEDIUM] CVE-2017-2635: A NULL pointer deference flaw was found in the way libvirt from 2
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
Red Hat
libvirt: Null pointer dereference when updating storage size on empty drives
vendor_redhat·2017-02-09·CVSS 7.7
CVE-2017-2635 [HIGH] CWE-476 libvirt: Null pointer dereference when updating storage size on empty drives
libvirt: Null pointer dereference when updating storage size on empty drives
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
A NULL pointer deference flaw was found in the way libvirt handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
Statement: This issue does not affect libvirt as shipped with Red Hat Enterprise Linux 5, 6 and 7 as it does not contain the affected code.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not aff
Debian
CVE-2017-2635: libvirt - A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 h...
vendor_debian·2017·CVSS 7.7
CVE-2017-2635 [HIGH] CVE-2017-2635: libvirt - A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 h...
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.0-3)
bullseye: resolved (fixed in 3.0.0-3)
forky: resolved (fixed in 3.0.0-3)
sid: resolved (fixed in 3.0.0-3)
trixie: resolved (fixed in 3.0.0-3)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2635https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=c3de387380f6057ee0e46cd9f2f0a092e8070875https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2635https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=c3de387380f6057ee0e46cd9f2f0a092e8070875
2018-08-22
Published