Debian Bug report logs -
#959447
libvirt: CVE-2020-12430
Reported by: Salvatore Bonaccorso <carnil@debian.org>
Date: Sat, 2 May 2020 13:33:01 UTC
Severity: important
Tags: security, upstream
Found in versions libvirt/5.0.0-4+deb10u1, libvirt/4.10.0-1, libvirt/6.0.0-6
Reply or subscribe to this bug.
Toggle useless messages
Report forwarded
to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, team@security.debian.org, Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org>
:
Bug#959447
; Package src:libvirt
.
(Sat, 02 May 2020 13:33:03 GMT) (full text, mbox, link).
Acknowledgement sent
to Salvatore Bonaccorso <carnil@debian.org>
:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, team@security.debian.org, Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org>
.
(Sat, 02 May 2020 13:33:03 GMT) (full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
Source: libvirt
Version: 6.0.0-6
Severity: important
Tags: security upstream
Control: found -1 5.0.0-4+deb10u1
Control: found -1 4.10.0-1
Hi,
The following vulnerability was published for libvirt.
CVE-2020-12430[0]:
| An issue was discovered in qemuDomainGetStatsIOThread in
| qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory
| leak was found in the virDomainListGetStats libvirt API that is
| responsible for retrieving domain statistics when managing QEMU
| guests. This flaw allows unprivileged users with a read-only
| connection to cause a memory leak in the domstats command, resulting
| in a potential denial of service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2020-12430
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12430
Regards,
Salvatore
Marked as found in versions libvirt/5.0.0-4+deb10u1.
Request was from Salvatore Bonaccorso <carnil@debian.org>
to submit@bugs.debian.org
.
(Sat, 02 May 2020 13:33:03 GMT) (full text, mbox, link).
Marked as found in versions libvirt/4.10.0-1.
Request was from Salvatore Bonaccorso <carnil@debian.org>
to submit@bugs.debian.org
.
(Sat, 02 May 2020 13:33:04 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sun May 3 10:20:00 2020;
Machine Name:
bembo
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.