Debian Libvirt vulnerabilities
83 known vulnerabilities affecting debian/libvirt.
Total CVEs
83
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM39LOW28
Vulnerabilities
Page 2 of 5
CVE-2020-10701P4MEDIUMCVSS 6.5fixed in libvirt 6.0.0-7 (bookworm)2020
CVE-2020-10701 [MEDIUM] CVE-2020-10701: libvirt - A missing authorization flaw was found in the libvirt API responsible for changi...
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot resp
debian
CVE-2021-3631P4MEDIUMCVSS 6.3fixed in libvirt 7.6.0-1 (bookworm)2021
CVE-2021-3631 [MEDIUM] CVE-2021-3631: libvirt - A flaw was found in libvirt while it generates SELinux MCS category pairs for VM...
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 7.6.0-1)
bullse
debian
CVE-2011-1146P4LOWCVSS 7.2fixed in libvirt 0.8.8-3 (bookworm)2011
CVE-2011-1146 [HIGH] CVE-2011-1146: libvirt - libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operati...
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6)
debian
CVE-2020-12430P4LOWCVSS 6.5fixed in libvirt 6.4.0-2 (bookworm)2020
CVE-2020-12430 [MEDIUM] CVE-2020-12430: libvirt - An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in l...
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats
debian
CVE-2013-4400P4HIGHCVSS 7.2fixed in libvirt 1.1.4-1 (bookworm)2013
CVE-2013-4400 [HIGH] CVE-2013-4400: libvirt - virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite ...
virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.
Scope: local
bookworm: resolved (fixed in 1.1.4-1)
bullseye: resolved (fixed in 1.1.4-1)
forky: resolved (fixed in 1.1.4-1)
sid: resolved (fixed in 1.1.4-1)
trixie: resolved (fixed
debian
CVE-2020-25637P4MEDIUMCVSS 6.7fixed in libvirt 6.8.0-1 (bookworm)2020
CVE-2020-25637 [MEDIUM] CVE-2020-25637: libvirt - A double free memory issue was found to occur in the libvirt API, in versions be...
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daem
debian
CVE-2017-2635P4HIGHCVSS 7.7fixed in libvirt 3.0.0-3 (bookworm)2017
CVE-2017-2635 [HIGH] CVE-2017-2635: libvirt - A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 h...
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.0-3)
bullseye: resolved (fixed in 3.0.0-3)
forky: resolved (fixed in 3.0.0-3)
sid: resolved (fixed in 3.0.0-3)
tri
debian
CVE-2019-3840P4MEDIUMCVSS 5.8fixed in libvirt 5.0.0-1 (bookworm)2019
CVE-2019-3840 [MEDIUM] CVE-2019-3840: libvirt - A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 i...
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.
Scope: local
bookworm: resolved (fixed in 5.0.0-1)
bullseye: resolved (fixed in 5.0.0-1)
forky: resolved (fixed in 5.0.0-1)
sid: re
debian
CVE-2024-4418P4LOWCVSS 6.2fixed in libvirt 10.3.0-1 (forky)2024
CVE-2024-4418 [MEDIUM] CVE-2024-4418: libvirt - A race condition leading to a stack use-after-free flaw was found in libvirt. Du...
A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNe
debian
CVE-2014-7823P4MEDIUMCVSS 5.0fixed in libvirt 1.2.9-4 (bookworm)2014
CVE-2014-7823 [MEDIUM] CVE-2014-7823: libvirt - The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only use...
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Scope: local
bookworm: resolved (fixed in 1.2.9-4)
bullseye: resolved (fixed in 1.2.9-4)
forky: resolved (fixed in 1.2.9-4)
sid: resolved (fixed in 1.2.9-4
debian
CVE-2015-5247P4MEDIUMCVSS 6.5fixed in libvirt 1.2.20-1 (bookworm)2015
CVE-2015-5247 [MEDIUM] CVE-2015-5247: libvirt - The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote au...
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
Scope: local
bookworm: resolved (fixed in 1.2.20-1)
bullseye: resolved (fixed in 1.2.20-1)
forky: resolved (fixed
debian
CVE-2014-3657P4MEDIUMCVSS 5.0fixed in libvirt 1.2.9-1 (bookworm)2014
CVE-2014-3657 [MEDIUM] CVE-2014-3657: libvirt - The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9...
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in
debian
CVE-2013-6456P4MEDIUMCVSS 5.8fixed in libvirt 1.2.3-1 (bookworm)2013
CVE-2013-6456 [MEDIUM] CVE-2013-6456: libvirt - The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local us...
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot
debian
CVE-2014-3633P4MEDIUMCVSS 5.8fixed in libvirt 1.2.8-2 (bookworm)2014
CVE-2014-3633 [MEDIUM] CVE-2014-3633: libvirt - The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1....
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 1.2.8-2)
bu
debian
CVE-2025-12748P4MEDIUMCVSS 5.5fixed in libvirt 11.10.0-1 (forky)2025
CVE-2025-12748 [MEDIUM] CVE-2025-12748: libvirt - A flaw was discovered in libvirt in the XML file processing. More specifically, ...
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead
debian
CVE-2025-13193P4LOWCVSS 5.5fixed in libvirt 11.10.0-1 (forky)2025
CVE-2025-13193 [MEDIUM] CVE-2025-13193: libvirt - A flaw was found in libvirt. External inactive snapshots for shut-down VMs are i...
A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 11.10.0-1)
sid: resolved (fixed in 11.
debian
CVE-2008-5086P4HIGHCVSS 7.2fixed in libvirt 0.4.6-10 (bookworm)2008
CVE-2008-5086 [HIGH] CVE-2008-5086: libvirt - Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is ...
Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.
Scope: local
bookworm: resolved (fixed in 0.4.6-10)
bullseye: resolved (fixed in 0.4.6-10)
forky: resolved (fixed in 0.4.6-10)
sid: resolved (fixed in 0.4.6-10)
trixie: resolved (
debian
CVE-2023-3750P4MEDIUMCVSS 6.5fixed in libvirt 9.0.0-4+deb12u1 (bookworm)2023
CVE-2023-3750 [MEDIUM] CVE-2023-3750: libvirt - A flaw was found in libvirt. The virStoragePoolObjListSearch function does not r...
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
Scope: local
bookworm: resolved (fixed in 9.0.0
debian
CVE-2013-4291P4MEDIUMCVSS 6.9fixed in libvirt 1.1.2-2 (bookworm)2013
CVE-2013-4291 [MEDIUM] CVE-2013-4291: libvirt - The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and...
The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.
Scope: local
bookworm: resolved (fixed in 1.1.2-2)
bullseye: resolved (fixed in 1.1.2-2)
forky: resolved (fixed in 1.1.2-2)
sid: resolved (fixed in 1.1
debian
CVE-2011-2511P4MEDIUMCVSS 4.0fixed in libvirt 0.9.2-7 (bookworm)2011
CVE-2011-2511 [MEDIUM] CVE-2011-2511: libvirt - Integer overflow in libvirt before 0.9.3 allows remote authenticated users to ca...
Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.
Scope: local
bookworm: resolved (fixed in 0.9.2-7)
bullseye: resolved (fixed in 0.9.2-7)
forky: resolved (fixed in 0.9.2-7)
sid: resolved
debian