Libvirt Security Notice: LSN-2013-0013
Crash of libvirtd when ACLs are active and events registered
Lifecycle
Reported on: |
20131002 |
Published on: |
20130927 |
Fixed on: |
20130927 |
Credits
See also
Description
When a connection to libvirtd is closed any event handlers registered
must be removed. When ACLs were active no identity was set when removing the
event handlers, so the operation was denied. Thus event handlers remained
connected to a client that had been freed.
Impact
An unprivileged user can cause a crash of the libvirtd daemon when
ACLs are active by registering one or more event handlers. This leads to a
denial of service.
Workaround
Remove access from unprivileged local users or block access to the
event APIs using ACLs
Affected product: libvirt
Alternative formats:
[xml] [text]