Debian Libvirt vulnerabilities
83 known vulnerabilities affecting debian/libvirt.
Total CVEs
83
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM39LOW28
Vulnerabilities
Page 5 of 5
CVE-2014-8136P4LOWCVSS 2.1fixed in libvirt 1.2.9-7 (bookworm)2014
CVE-2014-8136 [LOW] CVE-2014-8136: libvirt - The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in q...
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-7)
bullseye: resolved (fixed in 1.2.9-7)
forky: resolved (fixed in 1.2.9-7)
sid: resol
debian
CVE-2013-6436P4LOWCVSS 2.1fixed in libvirt 1.2.0-1 (bookworm)2013
CVE-2013-6436 [LOW] CVE-2013-6436: libvirt - The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 thr...
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
Scope: local
book
debian
CVE-2013-7336P4LOWCVSS 1.9fixed in libvirt 1.1.4-1 (bookworm)2013
CVE-2013-7336 [LOW] CVE-2013-7336: libvirt - The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt befor...
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.
Sco
debian
← Previous5 / 5