Skip to main content

Vendor/product archive

redhat / libvirt CVEs

Beta · best-effort

73 CVEs tagged to redhat / libvirt1 Critical, 14 High, 44 Medium, 14 Low, 0 Unrated.

CVE-2024-8235

Published Aug 30, 2024

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory resu…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3750

Published Jul 24, 2023

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attemptin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10701

Published May 27, 2021

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14339

Published Dec 3, 2020

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen aga…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25637

Published Oct 6, 2020

A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domai…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10703

Published Jun 2, 2020

A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its tar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12430

Published Apr 28, 2020

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10168

Published Aug 2, 2019

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the p…

CVSS 7.8 · High

CVE-2019-10167

Published Aug 2, 2019

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulatio…

CVSS 7.8 · High

CVE-2019-10166

Published Aug 2, 2019

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would per…

CVSS 7.8 · High

CVE-2016-10746

Published Apr 18, 2019

libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a dif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3840

Published Mar 27, 2019

A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use t…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 73 CVEsPage 1 of 3