PT-2014-1810 · Red Hat+4 · Libvirt-Devel+10

Luyao Huang

·

Published

2014-09-19

·

Updated

2024-06-15

·

CVE-2014-3633

CVSS v2.0

6.8

Medium

VectorAV:A/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 1.2.9 libvirt-client version 0.10.2 libvirt-devel version 0.10.2 libvirt-debuginfo version 0.10.2 libvirt-python version 0.10.2
Description The issue affects the confidentiality, integrity, and availability of protected information. It is related to the qemuDomainGetBlockIoTune function in qemu/qemu driver.c, which allows remote attackers to cause a denial of service or read sensitive heap information via a crafted blkiotune query. This query can trigger an out-of-bounds read when a disk has been hot-plugged or removed from the live image.
Recommendations For libvirt versions prior to 1.2.9, update to version 1.2.9 or later to resolve the issue. For libvirt-client version 0.10.2, consider disabling the qemuDomainGetBlockIoTune function as a temporary workaround until a patch is available. For libvirt-devel version 0.10.2, restrict access to the qemu/qemu driver.c module to minimize the risk of exploitation. For libvirt-debuginfo version 0.10.2, avoid using the blkiotune query in the affected API endpoint until the issue is resolved. For libvirt-python version 0.10.2, consider disabling the qemuDomainGetBlockIoTune function as a temporary workaround until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2236
BDU:2015-06009
BDU:2015-06010
BDU:2015-06011
BDU:2015-06012
BDU:2015-06013
BDU:2015-09147
BDU:2015-09148
BDU:2015-09149
BDU:2015-09150
BDU:2015-09151
CESA-2014_1352
CESA-2014_1873
CVE-2014-3633
DSA-3038-1
MGASA-2014-0401
OPENSUSE-SU-2024:10209-1
RHSA-2014:1352
RHSA-2014:1873
RHSA-2014_1352
RHSA-2014_1873
SUSE-SU-2015:0357-1
SUSE-SU-2015_0357-1
USN-2366-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libvirt
Libvirt-Client
Libvirt-Debuginfo
Libvirt-Devel
Libvirt-Python
Qemu