cbcvebase.

Redhat Libvirt vulnerabilities

90 known vulnerabilities affecting redhat/libvirt.

Total CVEs
90
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW15

Vulnerabilities

Page 3 of 5
CVE-2025-13193P4MEDIUMCVSS 5.5≥ 0, < 11.3.0-3+deb13u2≥ 0, < 11.10.0-12025-11-17
CVE-2025-13193 [MEDIUM] CVE-2025-13193: A flaw was found in libvirt A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect the guest OS contents. This results in an information disclosure vulnerability.
osv
CVE-2008-5086P4HIGHCVSS 7.2≥ 0, < 0.4.6-102008-12-19
CVE-2008-5086 [HIGH] CVE-2008-5086: Multiple methods in libvirt 0 Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.
osv
CVE-2013-1962P4MEDIUMCVSS 5.0v1.0.52013-05-29
CVE-2013-1962 [MEDIUM] CWE-399 CVE-2013-1962: The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 al The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."
nvd
CVE-2023-3750P4MEDIUMCVSS 5.3≥ 0, < 9.0.0-4+deb12u1≥ 0, < 9.6.0-12023-07-24
CVE-2023-3750 [MEDIUM] CVE-2023-3750: A flaw was found in libvirt A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
osv
CVE-2013-4291P4MEDIUMCVSS 6.9v0.10.2.7v1.0.5.5+1 more2013-09-30
CVE-2013-4291 [MEDIUM] CWE-264 CVE-2013-4291: The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the dom The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.
nvdosv
CVE-2011-2511P4MEDIUMCVSS 4.0≤ 0.9.2v0.0.1+56 more2011-08-10
CVE-2011-2511 [MEDIUM] CWE-189 CVE-2011-2511: Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of serv Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.
nvdosv
CVE-2021-4147P4MEDIUMCVSS 6.5fixed in 2.33.0vlibvirt 2.33.02022-03-25
CVE-2021-4147 [MEDIUM] CWE-667 CVE-2021-4147: A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
nvdosv
CVE-2012-4423P4MEDIUMCVSS 5.0≤ 0.10.1v0.0.1+69 more2012-11-19
CVE-2012-4423 [MEDIUM] CVE-2012-4423: The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cau The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.
nvdosv
CVE-2024-2494P4MEDIUMCVSS 6.2≥ 0, < 7.0.0-3+deb11u3≥ 0, < 9.0.0-4+deb12u1+1 more2024-03-21
CVE-2024-2494 [MEDIUM] CVE-2024-2494: A flaw was found in the RPC library APIs of libvirt A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attac
osv
CVE-2024-8235P4MEDIUMCVSS 6.2≥ 10.4.0, < 10.7.02024-08-30
CVE-2024-8235 [MEDIUM] CWE-476 CVE-2024-8235: A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple API A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash of virtinterfaced. This issue could allow clients connecting to the read
nvdosv
CVE-2013-4153P4MEDIUMCVSS 5.0v1.0.6v1.1.02013-09-30
CVE-2013-4153 [MEDIUM] CWE-399 CVE-2013-4153: Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 th Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the "virsh vcpucount dom --guest" command.
nvdosv
CVE-2015-5160P4MEDIUMCVSS 5.5≥ 0, < 2.2.0-12018-08-20
CVE-2015-5160 [MEDIUM] CVE-2015-5160: libvirt before 2 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
osv
CVE-2024-1441P4MEDIUMCVSS 5.5≥ 0, < 6.0.0-0ubuntu8.19≥ 0, < 8.0.0-1ubuntu7.102024-04-15
CVE-2024-1441 [MEDIUM] libvirt vulnerabilities libvirt vulnerabilities Alexander Kuznetsov discovered that libvirt incorrectly handled certain API calls. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2024-1441) It was discovered that libvirt incorrectly handled certain RPC library API calls. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2024-2494) It was discovered that
osv
CVE-2013-6457P4MEDIUMCVSS 5.2≤ 1.2.0v0.0.1+108 more2014-01-24
CVE-2013-6457 [MEDIUM] CWE-264 CVE-2013-6457: The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt befo The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.
nvdosv
CVE-2022-0897P4MEDIUMCVSS 4.3≤ 1.1.1vlibvirt 8.0.0-82022-03-25
CVE-2022-0897 [MEDIUM] CWE-667 CVE-2022-0897: A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit thi
nvdosv
CVE-2013-6458P4MEDIUMCVSS 6.8≤ 1.2.0v0.0.1+108 more2014-01-24
CVE-2013-6458 [MEDIUM] CWE-362 CVE-2013-6458: Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlo Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags comma
nvdosv
CVE-2014-3672P4MEDIUMCVSS 6.5≤ 1.2.212016-05-25
CVE-2014-3672 [MEDIUM] CWE-400 CVE-2014-3672: The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denia The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
nvd
CVE-2024-2496P4MEDIUMCVSS 5.5fixed in 9.8.02024-03-18
CVE-2024-2496 [MEDIUM] CWE-476 CVE-2024-2496: A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.
nvdosv
CVE-2013-4399P4MEDIUMCVSS 4.3≤ 1.1.3v0.0.1+106 more2014-12-12
CVE-2013-4399 [MEDIUM] CVE-2013-4399: The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, do The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
nvdosv
CVE-2011-2178P4MEDIUMCVSS 4.4v0.8.8v0.9.0+1 more2011-08-10
CVE-2011-2178 [MEDIUM] CVE-2011-2178: The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 throug The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of
nvdosv
Redhat Libvirt vulnerabilities | cvebase