CVE-2018-1064
published 2018-03-28CVE-2018-1064: libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.96%
85.6th percentile
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 4.1.0-1 (bookworm) | libvirt 4.1.0-1 (bookworm) |
| libvirt | libvirt | — | — |
| redhat | libvirt | <= 4.1.0 | — |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 4.1.0-1 | 4.1.0-1 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.27 | 1.2.2-0ubuntu13.1.27 |
| redhat | libvirt | >= 0 < 1.3.1-1ubuntu10.24 | 1.3.1-1ubuntu10.24 |
| redhat | libvirt | >= 0 < 4.0.0-1ubuntu8.2 | 4.0.0-1ubuntu8.2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerability and update
vendor_ubuntu·2018-06-12·CVSS 7.5
CVE-2018-1064 [HIGH] libvirt vulnerability and update
Title: libvirt vulnerability and update
Summary: Side channel execution mitigations were added to libvirt.
Ken Johnson and Jann Horn independently discovered that microprocessors
utilizing speculative execution of a memory read may allow unauthorized
memory reads via sidechannel attacks. An attacker in the guest could use
this to expose sensitive guest information, including kernel memory. This
update allows libvirt to expose new CPU features added by microcode updates
to guests. (CVE-2018-3639)
Daniel P. Berrange discovered that libvirt incorrectly handled the QEMU
guest agent. An attacker could possibly use this issue to consume
resources, leading to a denial of service. (CVE-2018-1064)
Instructions: After a standard system update you need to reboot your computer to make
all the nece
Red Hat
libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
vendor_redhat·2018-03-14·CVSS 7.5
CVE-2018-1064 [HIGH] CWE-400 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
An incomplete fix for CVE-2018-5748 that affects QEMU monitor leading to a resource exhaustion but now also triggered via QEMU guest agent.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1064: libvirt - libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a res...
vendor_debian·2018·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064: libvirt - libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a res...
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
Scope: local
bookworm: resolved (fixed in 4.1.0-1)
bullseye: resolved (fixed in 4.1.0-1)
forky: resolved (fixed in 4.1.0-1)
sid: resolved (fixed in 4.1.0-1)
trixie: resolved (fixed in 4.1.0-1)
GHSA
GHSA-r8xf-5287-837j: libvirt version before 4
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2018-1064 [HIGH] CWE-400 GHSA-r8xf-5287-837j: libvirt version before 4
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
OSV
libvirt vulnerability and update
osv·2018-06-12·CVSS 7.5
CVE-2018-3639 [HIGH] libvirt vulnerability and update
libvirt vulnerability and update
Ken Johnson and Jann Horn independently discovered that microprocessors
utilizing speculative execution of a memory read may allow unauthorized
memory reads via sidechannel attacks. An attacker in the guest could use
this to expose sensitive guest information, including kernel memory. This
update allows libvirt to expose new CPU features added by microcode updates
to guests. (CVE-2018-3639)
Daniel P. Berrange discovered that libvirt incorrectly handled the QEMU
guest agent. An attacker could possibly use this issue to consume
resources, leading to a denial of service. (CVE-2018-1064)
OSV
CVE-2018-1064: libvirt version before 4
osv·2018-03-28·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064: libvirt version before 4
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
bugzilla·2018-03-22·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
CVE-2018-1064 mingw-libvirt: libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
bugzilla·2018-03-01·CVSS 7.5
CVE-2018-1064 [HIGH] CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
CVE-2018-1064 libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent
An incomplete fix for CVE-2018-5748 that affects QEMU monitor leading to a resource exhaustion but now also triggered via QEMU guest agent.
Upstream patch:
https://libvirt.org/git/?p=libvirt.git;a=commit;h=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513
Discussion:
Created mingw-libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1559517]
---
Acknowledgments:
Name: Daniel P. Berrange (Red Hat)
---
External References:
https://security.libvirt.org/2018/0004.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1396 https://access.redhat.com/errata/RHSA-2018:1396
---
This issue has been addressed in the following products:
Red Hat E
https://access.redhat.com/errata/RHSA-2018:1396https://access.redhat.com/errata/RHSA-2018:1929https://bugzilla.redhat.com/show_bug.cgi?id=1550672https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513https://lists.debian.org/debian-lts-announce/2018/03/msg00018.htmlhttps://usn.ubuntu.com/3680-1/https://www.debian.org/security/2018/dsa-4137https://access.redhat.com/errata/RHSA-2018:1396https://access.redhat.com/errata/RHSA-2018:1929https://bugzilla.redhat.com/show_bug.cgi?id=1550672https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=fbf31e1a4cd19d6f6e33e0937a009775cd7d9513https://lists.debian.org/debian-lts-announce/2018/03/msg00018.htmlhttps://usn.ubuntu.com/3680-1/https://www.debian.org/security/2018/dsa-4137
2018-03-28
Published