Libvirt Security Notice: LSN-2026-0007

double free of a pointer in qemuAgentGetDisks

Lifecycle

Reported on: 20260819
Published on: 20260824
Fixed on: 20260824

Credits

Reported by: David Korczynski (Ada Logics)
Patched by: Ján Tomko

See also

Description

When processing of the disk data returned by the guest agent from the guest failed, hitting the cleanup label, the disks array was freed but the pointer was not cleared, leading to a possible double free.

Impact

Malicious guest OS can crash the libvirt daemon.

Workaround

Disable guest agent for utrusted guests

Affected product: libvirt

Branch: master

Broken in:
v7.0.0
v7.1.0
v7.2.0
v7.3.0
v7.4.0
v7.5.0
v7.6.0
v7.7.0
v7.8.0
v7.9.0
v7.10.0
v8.0.0
v8.1.0
v8.2.0
v8.3.0
v8.4.0
v8.5.0
v8.6.0
v8.7.0
v8.8.0
v8.9.0
v8.10.0
v9.0.0
v9.1.0
v9.2.0
v9.3.0
v9.4.0
v9.5.0
v9.6.0
v9.7.0
v9.8.0
v9.9.0
v9.10.0
v10.0.0
v10.1.0
v10.2.0
v10.3.0
v10.4.0
v10.5.0
v10.6.0
v10.7.0
v10.8.0
v10.9.0
v10.10.0
v11.0.0
v11.1.0
v11.2.0
v11.3.0
v11.4.0
v11.5.0
v11.6.0
v11.7.0
v11.8.0
v11.9.0
v11.10.0
v12.0.0
v12.1.0
v12.2.0
v12.3.0
v12.4.0
v12.5.0
v12.6.0
Fixed in:
v12.7.0
Broken by:
0cb2d9f05d00497a715352f6ea28cf8fb6921731
Fixed by:
9d3adf8db6da40a2e5966ca44989eedddc71a2f7

Alternative formats: [xml] [text]