PT-2020-6393 · Libvirt+1 · Libvirt+1
Marian Rehak
·
Published
2020-03-20
·
Updated
2024-06-15
·
CVE-2020-10701
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libvirt versions prior to 6.2.0
Description
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service.
Recommendations
For libvirt versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the libvirt API to prevent unprivileged users from adjusting the QEMU agent response timeout. Additionally, monitor guest agent commands for potential failures due to timeout issues.
Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libvirt