PT-2016-1796 · Libvirt+2 · Libvirt+2
Han Han
·
Published
2015-10-23
·
Updated
2024-06-15
·
CVE-2015-5247
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libvirt versions 1.2.14 through 1.2.19
Description
The issue is related to insufficient access control in the virStorageVolCreateXML API of the libvirt library, which manages virtualization. This can be exploited by a remote attacker to cause a denial of service, resulting in the libvirtd crash, by triggering a failed unlink after creating a volume on a root squash NFS pool.
Recommendations
For libvirt versions 1.2.14 through 1.2.19, consider restricting access to the virStorageVolCreateXML API to prevent remote authenticated users from exploiting the issue. As a temporary workaround, avoid using the virStorageVolCreateXML API to create volumes on root squash NFS pools until a patch is available.
Fix
DoS
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Ubuntu
Libvirt