Redhat Libvirt vulnerabilities
90 known vulnerabilities affecting redhat/libvirt.
Total CVEs
90
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW15
Vulnerabilities
Page 4 of 5
CVE-2019-20485P4MEDIUMCVSS 5.7fixed in 6.0.02020-03-19
CVE-2019-20485 [MEDIUM] CWE-20 CVE-2019-20485: qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
nvdosv
CVE-2013-5651P4MEDIUMCVSS 5.0≤ 1.1.1v0.0.1+104 more2013-09-30
CVE-2013-5651 [MEDIUM] CWE-119 CVE-2013-5651: The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent att
The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.
nvdosv
CVE-2019-3886P4MEDIUMCVSS 5.4≥ 4.8.0, < 5.3.02019-04-04
CVE-2019-3886 [MEDIUM] CWE-862 CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission wa
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
nvdosv
CVE-2023-2700P4MEDIUMCVSS 5.5v4.5.0vlibvirt-4.5.02023-05-15
CVE-2023-2700 [MEDIUM] CWE-401 CVE-2023-2700: A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IO
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
nvdosv
CVE-2013-4154P4MEDIUMCVSS 4.3≤ 1.1.0v1.0.0+6 more2013-09-30
CVE-2013-4154 [MEDIUM] CVE-2013-4154: The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
nvdosv
CVE-2010-2239P4MEDIUMCVSS 4.4≥ 0, < 0.8.3-12010-08-19
CVE-2010-2239 [MEDIUM] CVE-2010-2239: Red Hat libvirt, possibly 0
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
osv
CVE-2010-2238P4MEDIUMCVSS 4.4≥ 0, < 0.8.3-12010-08-19
CVE-2010-2238 [MEDIUM] CVE-2010-2238: Red Hat libvirt, possibly 0
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
osv
CVE-2010-2237P4MEDIUMCVSS 4.4≥ 0, < 0.8.3-12010-08-19
CVE-2010-2237 [MEDIUM] CVE-2010-2237: Red Hat libvirt, possibly 0
Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
osv
CVE-2014-0028P4MEDIUMCVSS 4.3v1.1.1v1.1.2+3 more2014-01-24
CVE-2014-0028 [MEDIUM] CWE-264 CVE-2014-0028: libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and conn
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
nvdosv
CVE-2013-4239P4MEDIUMCVSS 4.0v1.1.12013-09-30
CVE-2013-4239 [MEDIUM] CWE-119 CVE-2013-4239: The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authe
The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to cause a denial of service (memory corruption and crash) via vectors involving the virConnectListDefinedDomains API function.
nvdosv
CVE-2014-8131P4MEDIUMCVSS 4.0≤ 1.2.102015-01-06
CVE-2014-8131 [MEDIUM] CWE-264 CVE-2014-8131: The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly ha
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.
nvdosv
CVE-2015-0236P4LOWCVSS 3.5≤ 1.2.11v1.2.0+10 more2015-01-29
CVE-2015-0236 [LOW] CWE-200 CVE-2015-0236: libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_D
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
nvdosv
CVE-2013-4296P4MEDIUMCVSS 4.0v0.9.1v0.9.2+28 more2013-09-30
CVE-2013-4296 [MEDIUM] CWE-119 CVE-2013-4296: The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call.
nvdosv
CVE-2013-4297P4MEDIUMCVSS 4.0≤ 1.1.2v0.0.1+93 more2013-09-30
CVE-2013-4297 [MEDIUM] CWE-119 CVE-2013-4297: The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
nvdosv
CVE-2014-5177P4LOWCVSS 1.2v1.0.0v1.0.1+21 more2014-08-03
CVE-2014-5177 [LOW] CVE-2014-5177: libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStora
nvdosv
CVE-2013-2230P4MEDIUMCVSS 4.0≤ 1.1.0v0.0.1+91 more2013-09-30
CVE-2013-2230 [MEDIUM] CWE-20 CVE-2013-2230: The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to ca
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."
nvdosv
CVE-2013-4311P4MEDIUMCVSS 4.6v0.9.12v0.10.2+13 more2013-10-03
CVE-2013-4311 [MEDIUM] CVE-2013-4311: libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvdosv
CVE-2012-3445P4LOWCVSS 3.5v0.9.132012-08-07
CVE-2012-3445 [LOW] CWE-399 CVE-2012-3445: The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API c
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
nvdosv
CVE-2015-5313P4LOWCVSS 2.5≥ 0, < 1.3.0-12016-04-11
CVE-2015-5313 [LOW] CVE-2015-5313: Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.
osv
CVE-2014-1447P4LOWCVSS 3.3≤ 1.2.0v0.0.1+108 more2014-01-24
CVE-2014-1447 [LOW] CWE-362 CVE-2014-1447: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remot
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
nvdosv