| Reported on: | 20130805 |
|---|---|
| Published on: | 20130805 |
| Fixed on: | 20130805 |
| Reported by: | Jim Fehlig |
|---|---|
| Patched by: | Jim Fehlig |
The legacy Xen driver code for listing inactive domains would start populating an array at index -1. This causes memory corruption leading to a crash of libvirtd
An unprivileged user can crash libvirtd by requesting a list of inactive domains on a Xen host
Prevent untrusted users from accessing libvirtd