Redhat Libvirt vulnerabilities
67 known vulnerabilities affecting redhat/libvirt.
Total CVEs
67
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH11MEDIUM44LOW11
Vulnerabilities
Page 2 of 4
CVE-2019-10132HIGHCVSS 8.8≤ 4.1.02019-05-22
CVE-2019-10132 [HIGH] CWE-732 CVE-2019-10132: A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socke
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.
nvd
CVE-2016-10746HIGHCVSS 7.5fixed in 1.3.12019-04-18
CVE-2016-10746 [HIGH] CWE-254 CVE-2016-10746: libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
nvd
CVE-2019-3886MEDIUMCVSS 5.4≥ 4.8.0, < 5.3.02019-04-04
CVE-2019-3886 [MEDIUM] CWE-862 CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission wa
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
nvd
CVE-2019-3840MEDIUMCVSS 6.3fixed in 5.0.02019-03-27
CVE-2019-3840 [MEDIUM] CWE-476 CVE-2019-3840: A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets in
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.
nvd
CVE-2017-2635MEDIUMCVSS 6.5≥ 2.5.0, ≤ 3.0.02018-08-22
CVE-2017-2635 [HIGH] CWE-476 CVE-2017-2635: A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives.
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service.
nvd
CVE-2018-1064HIGHCVSS 7.5≤ 4.1.02018-03-28
CVE-2018-1064 [HIGH] CWE-400 CVE-2018-1064: libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
nvd
CVE-2017-1000256HIGHCVSS 8.1≥ 2.3.0, < 3.9.02017-10-31
CVE-2017-1000256 [HIGH] CWE-295 CVE-2017-1000256: libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" pas
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
nvd
CVE-2016-5008CRITICALCVSS 9.8≤ 1.3.52016-07-13
CVE-2016-5008 [CRITICAL] CWE-284 CVE-2016-5008: libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
nvd
CVE-2014-3672MEDIUMCVSS 6.5≤ 1.2.212016-05-25
CVE-2014-3672 [MEDIUM] CWE-400 CVE-2014-3672: The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denia
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
nvd
CVE-2015-5247MEDIUMCVSS 6.5v1.2.14v1.2.15+4 more2016-04-14
CVE-2015-5247 [MEDIUM] CWE-284 CVE-2015-5247: The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users wi
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
nvd
CVE-2011-4600MEDIUMCVSS 5.9v0.9.82016-04-14
CVE-2011-4600 [MEDIUM] CWE-284 CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
nvd
CVE-2015-0236LOWCVSS 3.5≤ 1.2.11v1.2.0+10 more2015-01-29
CVE-2015-0236 [LOW] CWE-200 CVE-2015-0236: libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_D
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
nvd
CVE-2014-8131MEDIUMCVSS 4.0≤ 1.2.102015-01-06
CVE-2014-8131 [MEDIUM] CWE-264 CVE-2014-8131: The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly ha
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
nvd
CVE-2013-4399MEDIUMCVSS 4.3≤ 1.1.3v0.0.1+106 more2014-12-12
CVE-2013-4399 [MEDIUM] CVE-2013-4399: The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, do
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
nvd
CVE-2014-7823MEDIUMCVSS 5.0≤ 1.2.10v1.2.0+9 more2014-11-13
CVE-2014-7823 [MEDIUM] CWE-255 CVE-2014-7823: The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
nvd
CVE-2014-0179LOWCVSS 1.9v0.7.5v0.7.6+69 more2014-08-03
CVE-2014-0179 [LOW] CWE-20 CVE-2014-0179: libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this is
nvd
CVE-2014-5177LOWCVSS 1.2v1.0.0v1.0.1+21 more2014-08-03
CVE-2014-5177 [LOW] CVE-2014-5177: libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStora
nvd
CVE-2013-7336LOWCVSS 1.9≤ 1.1.2v1.0.0+14 more2014-05-07
CVE-2013-7336 [LOW] CVE-2013-7336: The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not pro
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus functi
nvd
CVE-2013-6456MEDIUMCVSS 5.8v1.0.1v1.0.2+17 more2014-04-15
CVE-2013-6456 [MEDIUM] CWE-59 CVE-2013-6456: The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete ar
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shut
nvd
CVE-2013-6458MEDIUMCVSS 6.8≤ 1.2.0v0.0.1+108 more2014-01-24
CVE-2013-6458 [MEDIUM] CWE-362 CVE-2013-6458: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlo
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags comma
nvd