PT-2016-1796 · Libvirt+2 · Libvirt+2

Han Han

·

Published

2015-10-23

·

Updated

2024-06-15

·

CVE-2015-5247

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions 1.2.14 through 1.2.19
Description The issue is related to insufficient access control in the virStorageVolCreateXML API of the libvirt library, which manages virtualization. This can be exploited by a remote attacker to cause a denial of service, resulting in the libvirtd crash, by triggering a failed unlink after creating a volume on a root squash NFS pool.
Recommendations For libvirt versions 1.2.14 through 1.2.19, consider restricting access to the virStorageVolCreateXML API to prevent remote authenticated users from exploiting the issue. As a temporary workaround, avoid using the virStorageVolCreateXML API to create volumes on root squash NFS pools until a patch is available.

Fix

DoS

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1925
BDU:2016-01128
CVE-2015-5247
OPENSUSE-SU-2024:10209-1
USN-2867-1

Affected Products

Alt Linux
Ubuntu
Libvirt