PT-2020-6393 · Libvirt+1 · Libvirt+1

Marian Rehak

·

Published

2020-03-20

·

Updated

2024-06-15

·

CVE-2020-10701

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 6.2.0
Description A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service.
Recommendations For libvirt versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the libvirt API to prevent unprivileged users from adjusting the QEMU agent response timeout. Additionally, monitor guest agent commands for potential failures due to timeout issues.

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1681
ALT-PU-2021-1690
ALT-PU-2021-1965
AZL-6657
BDU:2021-04592
CVE-2020-10701
OPENSUSE-SU-2024:11008-1

Affected Products

Alt Linux
Libvirt