CVE-2013-6458

Related Vulnerabilities: CVE-2013-6458  

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

The MITRE CVE dictionary describes this issue as:

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

Find out more about CVE-2013-6458 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Red Hat Enterprise Linux 5 is now in Production 3 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

CVSS v2 metrics

Base Score 6.8
Base Metrics AV:A/AC:H/Au:N/C:C/I:C/A:C
Access Vector Adjacent Network
Access Complexity High
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (libvirt) RHSA-2014:0103 2014-01-28

Affected Packages State

Platform Package State
Red Hat Gluster Storage 2.1 libvirt Will not fix
Red Hat Gluster Storage 2.0 libvirt Will not fix
Red Hat Enterprise Linux 7 libvirt Not affected
Red Hat Enterprise Linux 5 libvirt Will not fix