Libvirt 'qemu/qemu_driver.c' DoS Vulnerability
Release date:
Updated on:
Affected Systems:
Libvirt
Description:
Bugtraq id: 71782
CVE (CAN) ID: CVE-2014-8136
The Libvirt library is a Linux API for implementing Linux virtualization. It supports various hypervisors, including Xen and KVM, QEMU, and some virtual products for other operating systems.
In libvirt, qemuDomainMigratePerform and qemuDomainMigrateFinish2 functions of qemu/qemu_driver.c do not enable the domain after the ACL check fails. Therefore, a security vulnerability exists in the implementation.
<* Source: Luyao Huang
*>
Suggestion:
Vendor patch:
Libvirt
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libvirt.org/index.html
Getting started with Linux: Changing the default location of libvirt VM Images
Experience containers in libvirt
Use libvirt to create and manage KVM virtual machines
Use Libvirt to connect to the KVM virtualization platform
This article permanently updates the link address: