Redhat Libvirt vulnerabilities
90 known vulnerabilities affecting redhat/libvirt.
Total CVEs
90
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW15
Vulnerabilities
Page 1 of 5
CVE-2018-3639P1HIGHCVSS 7.5ExploitedPoCRansomware≥ 0, < 1.2.2-0ubuntu13.1.27≥ 0, < 1.3.1-1ubuntu10.24+1 more2018-06-12
CVE-2018-3639 [HIGH] libvirt vulnerability and update
libvirt vulnerability and update
Ken Johnson and Jann Horn independently discovered that microprocessors
utilizing speculative execution of a memory read may allow unauthorized
memory reads via sidechannel attacks. An attacker in the guest could use
this to expose sensitive guest information, including kernel memory. This
update allows libvirt to expose new CPU features added by microcode updates
to guests. (CVE-2018-3639)
Daniel P. Berrang
osv
CVE-2016-5008P2CRITICALCVSS 9.8≤ 1.3.52016-07-13
CVE-2016-5008 [CRITICAL] CWE-284 CVE-2016-5008: libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
nvdosv
CVE-2013-2218P4MEDIUMCVSS 5.0PoCv1.0.62013-09-30
CVE-2013-2218 [MEDIUM] CWE-399 CVE-2013-2218: Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_n
Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.
nvdosv
CVE-2019-10132P3HIGHCVSS 8.8≤ 4.1.02019-05-22
CVE-2019-10132 [HIGH] CWE-732 CVE-2019-10132: A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socke
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
nvdosv
CVE-2020-14339P3HIGHCVSS 8.8≥ 6.2.0, < 6.7.0vlibvirt 6.6.02020-12-03
CVE-2020-14339 [HIGH] CWE-772 CVE-2020-14339: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QE
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing seriou
nvdosv
CVE-2009-0036P4MEDIUMCVSS 4.4PoC≥ 0, < 0.5.1-72009-02-11
CVE-2009-0036 [MEDIUM] CVE-2009-0036: Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy
Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.
osv
CVE-2019-10167P3HIGHCVSS 7.8≥ 4.0.0, < 4.10.1≥ 5.0.0, < 5.4.12019-08-02
CVE-2019-10167 [HIGH] CWE-250 CVE-2019-10167: The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, caus
nvdosv
CVE-2019-10168P3HIGHCVSS 7.8≥ 4.0.0, < 4.10.1≥ 5.0.0, < 5.4.12019-08-02
CVE-2019-10168 [HIGH] CWE-250 CVE-2019-10168: The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x befor
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary pat
nvdosv
CVE-2019-10166P3HIGHCVSS 7.8≥ 4.0.0, < 4.10.1≥ 5.0.0, < 5.4.12019-08-02
CVE-2019-10166 [HIGH] CWE-284 CVE-2019-10166: It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit r
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would
nvdosv
CVE-2020-15708P3HIGHCVSS 7.8≥ 0, < 6.0.0-0ubuntu8.32020-08-04
CVE-2020-15708 [HIGH] CVE-2020-15708: Ubuntu's packaging of libvirt in 20
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
osv
CVE-2013-4401P3HIGHCVSS 8.5v1.1.0v1.1.1+2 more2013-11-02
CVE-2013-4401 [HIGH] CWE-264 CVE-2013-4401: The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:r
The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.
nvdosv
CVE-2016-10746P3HIGHCVSS 7.5fixed in 1.3.12019-04-18
CVE-2016-10746 [HIGH] CWE-254 CVE-2016-10746: libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
nvdosv
CVE-2019-10161P3HIGHCVSS 7.8fixed in 4.10.1≥ 5.0.0, < 5.4.12019-07-30
CVE-2019-10161 [HIGH] CWE-284 CVE-2019-10161: It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to u
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause
nvdosv
CVE-2017-1000256P3HIGHCVSS 8.1≥ 2.3.0, < 3.9.02017-10-31
CVE-2017-1000256 [HIGH] CWE-295 CVE-2017-1000256: libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" pas
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
nvdosv
CVE-2018-6764P3HIGHCVSS 7.8≥ 0, < 4.0.0-22018-02-23
CVE-2018-6764 [HIGH] CVE-2018-6764: util/virlog
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
osv
CVE-2020-14301P3MEDIUMCVSS 6.5≥ 6.2.0, < 6.3.0vlibvirt 6.3.02021-05-27
CVE-2020-14301 [MEDIUM] CWE-212 CVE-2020-14301: An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
nvd
CVE-2018-1064P3HIGHCVSS 7.5≤ 4.1.02018-03-28
CVE-2018-1064 [HIGH] CWE-400 CVE-2018-1064: libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
nvdosv
CVE-2013-0170P3MEDIUMCVSS 6.8≥ 0.9.6, < 0.9.6.4≥ 0.9.11, < 0.9.11.9+2 more2013-02-08
CVE-2013-0170 [MEDIUM] CWE-416 CVE-2013-0170: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvir
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which
nvdosv
CVE-2021-3559P3MEDIUMCVSS 6.5≥ 6.10.0, < 7.0.0vlibvirt 7.0.02021-05-24
CVE-2021-3559 [MEDIUM] CWE-119 CVE-2021-3559: A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It onl
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The
nvdosv
CVE-2011-4600P3MEDIUMCVSS 5.9v0.9.82016-04-14
CVE-2011-4600 [MEDIUM] CWE-284 CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
nvdosv
1 / 5Next →