PT-2020-10467 · Libvirt+6 · Libvirt+6

Salvatore Bonaccorso

·

Published

2020-01-25

·

Updated

2023-02-03

·

CVE-2019-20485

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 6.0.0
Description The issue is related to the mishandling of the holding of a monitor job during a query to a guest agent in the qemu/qemu driver.c file. This allows attackers to cause a denial of service, resulting in API blockage.
Recommendations For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the guest agent query functionality to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4676
ALT-PU-2020-1097
ALT-PU-2021-1690
ALT-PU-2021-1965
CESA-2020_4000
CESA-2020_4676
CVE-2019-20485
MGASA-2020-0283
RHSA-2020:4000
RHSA-2020:4676
RHSA-2020_4000
RHSA-2020_4676
RLSA-2020:4676

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Red Hat
Rocky Linux
Libvirt