| Reported on: | 20130716 |
|---|---|
| Published on: | 20130716 |
| Fixed on: | 20130716 |
| Reported by: | Alex Jia |
|---|---|
| Patched by: | Alex Jia |
If the qemu guest agent service is not present in a guest then the libvirtd daemon will crash on a NULL pointer when trying to run guest agent related commands.
A user with the permission to invoke APIs which talk to the guest agent will be able to crash the libvirtd daemon leading to a denial of service.
Prevent untrusted users from executing APIs which talk to the guest agent by removing their ability to connect to libvirtd or deny the permission bits in the access control policy.