CVE-2019-20485
published 2020-03-19CVE-2019-20485: qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of…
PriorityP419medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
EPSS
0.81%
52.9th percentile
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 6.0.0-2 (bookworm) | libvirt 6.0.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | libvirt | < 6.0.0 | 6.0.0 |
| redhat | libvirt | >= 0 < 6.0.0-2 | 6.0.0-2 |
| redhat | libvirt | >= 0 < 6.0.0-2 | 6.0.0-2 |
| redhat | libvirt | >= 0 < 6.0.0-2 | 6.0.0-2 |
| redhat | libvirt | >= 0 < 6.0.0-2 | 6.0.0-2 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv5.7MEDIUM
vendor_debian5.7LOW
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9283-64xm-984q: qemu/qemu_driver
ghsa_unreviewed·2022-05-24
CVE-2019-20485 [LOW] CWE-20 GHSA-9283-64xm-984q: qemu/qemu_driver
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
OSV
CVE-2019-20485: qemu/qemu_driver
osv·2020-03-19·CVSS 5.7
CVE-2019-20485 [MEDIUM] CVE-2019-20485: qemu/qemu_driver
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
Red Hat
libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
vendor_redhat·2019-12-05·CVSS 5.7
CVE-2019-20485 [MEDIUM] CWE-400 libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
A flaw was found in the way the libvirtd daemon issued the 'suspend' command to a QEMU guest-agent running inside a guest, where it holds a monitor job while issuing the 'suspend' command to a guest-agent. A malicious guest-agent may use this flaw to block the libvirt daemon indefinitely, resulting in a denial of service.
Statement: This issue affects the version of the libvirt package as shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt updates for Red Hat Enterpr
Debian
CVE-2019-20485: libvirt - qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor j...
vendor_debian·2019·CVSS 5.7
CVE-2019-20485 [MEDIUM] CVE-2019-20485: libvirt - qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor j...
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
Scope: local
bookworm: resolved (fixed in 6.0.0-2)
bullseye: resolved (fixed in 6.0.0-2)
forky: resolved (fixed in 6.0.0-2)
sid: resolved (fixed in 6.0.0-2)
trixie: resolved (fixed in 6.0.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20485 libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [fedora-all]
bugzilla·2020-03-03·CVSS 5.7
CVE-2019-20485 [MEDIUM] CVE-2019-20485 libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [fedora-all]
CVE-2019-20485 libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2019-20485 libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
bugzilla·2020-03-03·CVSS 5.7
CVE-2019-20485 [MEDIUM] CVE-2019-20485 libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
CVE-2019-20485 libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent
A flaw was found in the way Libvirtd daemon issued the 'suspend' command to a QEMU guest-agent running inside a guest. It holds a monitor job while issuing the 'suspend' command to a guest-agent. A malicious guest-agent may use this flaw to block the Libvirt daemon indefinitely resulting in a DoS scenario.
Upstream patch:
-> https://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=a663a860819287e041c3de672aad1d8543098ecc
Discussion:
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1809741]
---
Acknowledgments:
Name: Eric Blake (Red Hat Inc.)
---
Statement:
This issue affects the version of the libvirt package as shipped with Red Hat Enterprise Linux 7, 8 and Red Hat
Bugzilla
CVE-2019-20485 virt:8.1/libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [rhel-av-8]
bugzilla·2019-10-08·CVSS 5.7
CVE-2019-20485 [MEDIUM] CVE-2019-20485 virt:8.1/libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [rhel-av-8]
CVE-2019-20485 virt:8.1/libvirt: potential DoS by holding a monitor job while querying QEMU guest-agent [rhel-av-8]
+++ This bug was initially created as a clone of Bug #1705426 +++
It is possible to call some QEMU-GA commands using libvirt interface (e.g. virDomainInterfaceAddresses) but all the commands block until the call to QEMU-GA finishes and it is not possible to specify a timeout. This is problematic for example in situations when the guest is under load when the call can take some time to finish. For the duration the libvirt domain is locked and any other interaction with libvirt is impossible.
The libvirt interface should be extended to allow setting a timeout to the guest agent calls.
--- Additional comment from Daniel Berrangé on 2019-05-02 09:24:38 UTC ---
(In reply to T
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953078https://bugzilla.redhat.com/show_bug.cgi?id=1809740https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=a663a860819287e041c3de672aad1d8543098ecchttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/https://security-tracker.debian.org/tracker/CVE-2019-20485https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1730509.htmlhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953078https://bugzilla.redhat.com/show_bug.cgi?id=1809740https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=a663a860819287e041c3de672aad1d8543098ecchttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/https://security-tracker.debian.org/tracker/CVE-2019-20485https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1730509.html
2020-03-19
Published