The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-2093-1 | vendor advisory |
http://osvdb.org/101485 | vdb entry |
http://secunia.com/advisories/60895 | third party advisory |
http://security.gentoo.org/glsa/glsa-201412-04.xml | vendor advisory |
http://secunia.com/advisories/56245 | third party advisory |
http://lists.opensuse.org/opensuse-updates/2014-01/msg00004.html | vendor advisory |
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f8c1cb90213508c4f32549023b0572ed774e48aa | |
https://www.redhat.com/archives/libvir-list/2013-December/msg01170.html | mailing list |