Libvirt Security Notice: LSN-2013-0006
Crash of libvirtd without guest agent active
Lifecycle
Reported on: |
20130716 |
Published on: |
20130716 |
Fixed on: |
20130716 |
Credits
See also
Description
If the qemu guest agent service is not present in a guest
then the libvirtd daemon will crash on a NULL pointer when trying
to run guest agent related commands.
Impact
A user with the permission to invoke APIs which talk to
the guest agent will be able to crash the libvirtd daemon leading
to a denial of service.
Workaround
Prevent untrusted users from executing APIs which talk
to the guest agent by removing their ability to connect to libvirtd
or deny the permission bits in the access control policy.
Affected product: libvirt
Alternative formats:
[xml] [text]