CVE-2013-6458
Last modified
CVE-2013-6458 is a vulnerability of currently unknown severity. Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Libvirt | <= 1.2.0 |
| Redhat | Libvirt | 0.0.1 |
| Redhat | Libvirt | 0.0.2 |
| Redhat | Libvirt | 0.0.3 |
| Redhat | Libvirt | 0.0.4 |
| Redhat | Libvirt | 0.0.5 |
| Redhat | Libvirt | 0.0.6 |
| Redhat | Libvirt | 0.1.0 |
| Redhat | Libvirt | 0.1.1 |
| Redhat | Libvirt | 0.1.3 |
| Redhat | Libvirt | 0.1.4 |
| Redhat | Libvirt | 0.1.5 |
| Redhat | Libvirt | 0.1.6 |
| Redhat | Libvirt | 0.1.7 |
| Redhat | Libvirt | 0.1.8 |
| Redhat | Libvirt | 0.1.9 |
| Redhat | Libvirt | 0.2.0 |
| Redhat | Libvirt | 0.2.1 |
| Redhat | Libvirt | 0.2.2 |
| Redhat | Libvirt | 0.2.3 |
| Redhat | Libvirt | 0.3.0 |
| Redhat | Libvirt | 0.3.1 |
| Redhat | Libvirt | 0.3.2 |
| Redhat | Libvirt | 0.3.3 |
| Redhat | Libvirt | 0.4.0 |
| Redhat | Libvirt | 0.4.1 |
| Redhat | Libvirt | 0.4.2 |
| Redhat | Libvirt | 0.4.3 |
| Redhat | Libvirt | 0.4.4 |
| Redhat | Libvirt | 0.4.5 |
| Redhat | Libvirt | 0.4.6 |
| Redhat | Libvirt | 0.5.0 |
| Redhat | Libvirt | 0.5.1 |
| Redhat | Libvirt | 0.6.0 |
| Redhat | Libvirt | 0.6.1 |
| Redhat | Libvirt | 0.6.2 |
| Redhat | Libvirt | 0.6.3 |
| Redhat | Libvirt | 0.6.4 |
| Redhat | Libvirt | 0.6.5 |
| Redhat | Libvirt | 0.7.0 |
| Redhat | Libvirt | 0.7.1 |
| Redhat | Libvirt | 0.7.2 |
| Redhat | Libvirt | 0.7.3 |
| Redhat | Libvirt | 0.7.4 |
| Redhat | Libvirt | 0.7.5 |
| Redhat | Libvirt | 0.7.6 |
| Redhat | Libvirt | 0.7.7 |
| Redhat | Libvirt | 0.8.0 |
| Redhat | Libvirt | 0.8.1 |
| Redhat | Libvirt | 0.8.2 |
Showing 50 of 110 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/56186Vendor Advisory
- http://secunia.com/advisories/56446Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1043069Vendor Advisory
- http://secunia.com/advisories/56186Vendor Advisory
- http://secunia.com/advisories/56446Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1043069Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-6458?
How severe is CVE-2013-6458?
How do I fix CVE-2013-6458?
Are you affected by CVE-2013-6458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
