Libvirt Security Notice: LSN-2017-0001
libvirtd crashes in virConnectGetAllDomainStats with empty cdrom
Lifecycle
Reported on: |
20170224 |
Published on: |
20170224 |
Fixed on: |
20170224 |
Credits
See also
Description
When calling the virConnectGetAllDomainStats API on a guest which has
a CDROM drive with no media present, libvirtd will crash on a NULL pointer
access
Impact
An application can cause a denial of service by crashing libvirtd if
a guest has a CDROM drive with no media
Workaround
Avoid calling the virConnectGetAllDomainStats API, or ensure all CDROM
drives have media inserted
Affected product: libvirt
Alternative formats:
[xml] [text]