LWN.net Logo

libvirt: denial of service

Package(s):libvirt CVE #(s):CVE-2013-1962
Created:May 17, 2013 Updated:July 3, 2013
Description:

From the Red Hat advisory:

It was found that libvirtd leaked file descriptors when listing all volumes for a particular pool. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to cause libvirtd to consume all available file descriptors, preventing other users from using libvirtd services (such as starting a new guest) until libvirtd is restarted.

Alerts:
Red Hat RHSA-2013:0831-01 2013-05-16
CentOS CESA-2013:0831 2013-05-17
Oracle ELSA-2013-0831 2013-05-16
Scientific Linux SL-libv-20130516 2013-05-16
Fedora FEDORA-2013-8681 2013-05-29
Mageia MGASA-2013-0166 2013-06-06
openSUSE openSUSE-SU-2013:0885-1 2013-06-10
Ubuntu USN-1895-1 2013-07-02
Gentoo 201309-18 2013-09-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds