2.1
CVSSv2

CVE-2014-8135

Published: 19/12/2014 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The storageVolUpload function in storage/storage_driver.c in libvirt prior to 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt -

Vendor Advisories

Debian Bug report logs - #773856 CVE-2014-8136 deadlock on failed migration Package: src:libvirt; Maintainer for src:libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Guido Günther <agx@sigxcpuorg> Date: Wed, 24 Dec 2014 08:39:07 UTC Severity: important Tags: fixe ...
Debian Bug report logs - #773855 CVE-2014-8135 crash when using virStorageVolUpload Package: src:libvirt; Maintainer for src:libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Guido Günther <agx@sigxcpuorg> Date: Wed, 24 Dec 2014 08:39:02 UTC Severity: grave Tags: ...
Debian Bug report logs - #773858 CVE-2014-8131 deadlock or segfault in virConnectGetAllDomainStats Package: src:libvirt; Maintainer for src:libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Guido Günther <agx@sigxcpuorg> Date: Wed, 24 Dec 2014 08:39:17 UTC Severit ...
The storageVolUpload function in storage/storage_driverc in libvirt before 1211 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command ...