Memory Leak Affecting libvirt-daemon-driver-lxc package, versions <0:5.7.0-15.el7
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ORACLE7-LIBVIRTDAEMONDRIVERLXC-2575589
- published 10 Apr 2022
- disclosed 28 Apr 2020
Introduced: 28 Apr 2020
CVE-2020-12430 Open this link in a new tabHow to fix?
Upgrade Oracle:7 libvirt-daemon-driver-lxc to version 0:5.7.0-15.el7 or higher.
This issue was patched in ELSA-2020-5719.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libvirt-daemon-driver-lxc package and not the libvirt-daemon-driver-lxc package as distributed by Oracle.
See How to fix? for Oracle:7 relevant fixed versions and status.
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
References
- https://linux.oracle.com/cve/CVE-2020-12430.html
- https://linux.oracle.com/errata/ELSA-2020-5719.html
- https://linux.oracle.com/errata/ELSA-2020-5720.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1804548
- https://bugzilla.redhat.com/show_bug.cgi?id=1828190
- https://libvirt.org/git/?p=libvirt.git;a=commit;h=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581
- https://security.netapp.com/advisory/ntap-20200518-0003/
- https://usn.ubuntu.com/4371-1/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/
- https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=9bf9e0ae6af38c806f4672ca7b12a6b38d5a9581
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D5GE6ISYUL3CIWO3FQRUGMKTKP2NYED2/
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html