Libvirt Security Notice: LSN-2013-0005
Crash after querying vCPU count from guest agent
Lifecycle
Reported on: |
20130716 |
Published on: |
20130716 |
Fixed on: |
20130716 |
Credits
See also
Description
When processing the response to a vCPU count query from
the guest agent, a JSON object would be freed twice. This could
result in a crash of the libvirtd daemon.
Impact
A user with permission to query the VCPU count could
crash the libvirtd daemon resulting in a denial of service.
Workaround
Prevent untrusted users from accessing libvirtd
Affected product: libvirt
Alternative formats:
[xml] [text]