cbcvebase.

Redhat Libvirt vulnerabilities

90 known vulnerabilities affecting redhat/libvirt.

Total CVEs
90
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW15

Vulnerabilities

Page 2 of 5
CVE-2021-3667P4MEDIUMCVSS 6.5≥ 4.1.0, ≤ 7.5.0vFixedin - libvert v7.6.0-rc1 and above2022-03-02
CVE-2021-3667 [MEDIUM] CWE-667 CVE-2021-3667: An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occur An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock
nvdosv
CVE-2018-5748P4HIGHCVSS 7.5≥ 0, < 4.0.0-12018-01-25
CVE-2018-5748 [HIGH] CVE-2018-5748: qemu/qemu_monitor qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
osv
CVE-2020-10703P4MEDIUMCVSS 6.5≥ 3.10.0, < 6.0.02020-06-02
CVE-2020-10703 [MEDIUM] CWE-476 CVE-2020-10703: A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3 A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as network-based pools like gluster and RBD. Unprivileged users with a read-onl
nvdosv
CVE-2021-3975P4MEDIUMCVSS 6.5fixed in 7.1.0vFixed in libvirt v7.1.02022-08-23
CVE-2021-3975 [MEDIUM] CWE-416 CVE-2021-3975: A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandl A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection co
nvdosv
CVE-2020-10701P4MEDIUMCVSS 6.5fixed in 6.2.0vlibvirt 6.2.02021-05-27
CVE-2020-10701 [MEDIUM] CWE-862 CVE-2020-10701: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent re A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the ag
nvdosv
CVE-2021-3631P4MEDIUMCVSS 6.3fixed in 7.5.0vFixed-In - libvirt v7.5.02022-03-02
CVE-2021-3631 [MEDIUM] CWE-732 CVE-2021-3631: A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. T A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
nvdosv
CVE-2011-1146P4MEDIUMCVSS 6.9v0.8.82011-03-15
CVE-2011-1146 [MEDIUM] CVE-2011-1146: libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only c libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttac
nvdosv
CVE-2020-12430P4MEDIUMCVSS 6.5≥ 4.10.0, < 6.1.02020-04-28
CVE-2020-12430 [MEDIUM] CWE-401 CVE-2020-12430: An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak
nvdosv
CVE-2013-4400P4HIGHCVSS 7.2v1.1.2v1.1.32013-12-09
CVE-2013-4400 [HIGH] CWE-264 CVE-2013-4400: virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.
nvdosv
CVE-2020-25637P4MEDIUMCVSS 6.7fixed in 6.8.0vlibvirt versions before 6.8.02020-10-06
CVE-2020-25637 [MEDIUM] CWE-415 CVE-2020-25637: A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsi A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash t
nvdosv
CVE-2017-2635P4MEDIUMCVSS 6.5≥ 2.5.0, ≤ 3.0.02018-08-22
CVE-2017-2635 [MEDIUM] CWE-476 CVE-2017-2635: A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
nvdosv
CVE-2019-3840P4MEDIUMCVSS 6.3fixed in 5.0.02019-03-27
CVE-2019-3840 [MEDIUM] CWE-476 CVE-2019-3840: A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets in A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.
nvdosv
CVE-2024-4418P4MEDIUMCVSS 6.2≥ 0, < 10.3.0-12024-05-08
CVE-2024-4418 [MEDIUM] CVE-2024-4418: A race condition leading to a stack use-after-free flaw was found in libvirt A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoo
osv
CVE-2014-7823P4MEDIUMCVSS 5.0≤ 1.2.10v1.2.0+9 more2014-11-13
CVE-2014-7823 [MEDIUM] CWE-255 CVE-2014-7823: The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
nvdosv
CVE-2015-5247P4MEDIUMCVSS 6.5v1.2.14v1.2.15+4 more2016-04-14
CVE-2015-5247 [MEDIUM] CWE-284 CVE-2015-5247: The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users wi The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
nvdosv
CVE-2014-3657P4MEDIUMCVSS 5.0≥ 0, < 1.2.9-12014-10-06
CVE-2014-3657 [MEDIUM] CVE-2014-3657: The virDomainListPopulate function in conf/domain_conf The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
osv
CVE-2013-6456P4MEDIUMCVSS 5.8v1.0.1v1.0.2+17 more2014-04-15
CVE-2013-6456 [MEDIUM] CWE-59 CVE-2013-6456: The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete ar The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shut
nvdosv
CVE-2018-12130P4MEDIUMCVSS 5.6≥ 0, < 1.3.1-1ubuntu10.26≥ 0, < 4.0.0-1ubuntu8.102019-05-15
[MEDIUM] libvirt update libvirt update Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss discovered that memory previously stored in microarchitectural fill buffers of an Intel CPU core may be exposed to a malicious process that is executing on the same CPU core
osv
CVE-2014-3633P4MEDIUMCVSS 5.8≥ 0, < 1.2.8-22014-10-06
CVE-2014-3633 [MEDIUM] CVE-2014-3633: The qemuDomainGetBlockIoTune function in qemu/qemu_driver The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
osv
CVE-2025-12748P4MEDIUMCVSS 5.5≥ 0, < 11.3.0-3+deb13u2≥ 0, < 11.10.0-12025-11-11
CVE-2025-12748 [MEDIUM] CVE-2025-12748: A flaw was discovered in libvirt in the XML file processing A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a specially crafted XML file, causing libvirt to allocate too much memory on the host. The excessive memory consumption could lead to a libvirt process crash on the
osv
Redhat Libvirt vulnerabilities | cvebase