CVE-2013-6458
Summary
| CVE | CVE-2013-6458 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-24 18:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:A/AC:H/Au:N/C:C/I:C/A:C
EPSS: 0.008920000 probability, percentile 0.756600000 (date 2026-05-03)
Problem Types: CWE-362 | n/a
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:A/AC:H/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Libvirt | 0.0.1 | All | All | All |
| Application | Redhat | Libvirt | 0.0.2 | All | All | All |
| Application | Redhat | Libvirt | 0.0.3 | All | All | All |
| Application | Redhat | Libvirt | 0.0.4 | All | All | All |
| Application | Redhat | Libvirt | 0.0.5 | All | All | All |
| Application | Redhat | Libvirt | 0.0.6 | All | All | All |
| Application | Redhat | Libvirt | 0.1.0 | All | All | All |
| Application | Redhat | Libvirt | 0.1.1 | All | All | All |
| Application | Redhat | Libvirt | 0.1.3 | All | All | All |
| Application | Redhat | Libvirt | 0.1.4 | All | All | All |
| Application | Redhat | Libvirt | 0.1.5 | All | All | All |
| Application | Redhat | Libvirt | 0.1.6 | All | All | All |
| Application | Redhat | Libvirt | 0.1.7 | All | All | All |
| Application | Redhat | Libvirt | 0.1.8 | All | All | All |
| Application | Redhat | Libvirt | 0.1.9 | All | All | All |
| Application | Redhat | Libvirt | 0.10.0 | All | All | All |
| Application | Redhat | Libvirt | 0.10.1 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.1 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.2 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.3 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.4 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.5 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.6 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.7 | All | All | All |
| Application | Redhat | Libvirt | 0.10.2.8 | All | All | All |
| Application | Redhat | Libvirt | 0.2.0 | All | All | All |
| Application | Redhat | Libvirt | 0.2.1 | All | All | All |
| Application | Redhat | Libvirt | 0.2.2 | All | All | All |
| Application | Redhat | Libvirt | 0.2.3 | All | All | All |
| Application | Redhat | Libvirt | 0.3.0 | All | All | All |
| Application | Redhat | Libvirt | 0.3.1 | All | All | All |
| Application | Redhat | Libvirt | 0.3.2 | All | All | All |
| Application | Redhat | Libvirt | 0.3.3 | All | All | All |
| Application | Redhat | Libvirt | 0.4.0 | All | All | All |
| Application | Redhat | Libvirt | 0.4.1 | All | All | All |
| Application | Redhat | Libvirt | 0.4.2 | All | All | All |
| Application | Redhat | Libvirt | 0.4.3 | All | All | All |
| Application | Redhat | Libvirt | 0.4.4 | All | All | All |
| Application | Redhat | Libvirt | 0.4.5 | All | All | All |
| Application | Redhat | Libvirt | 0.4.6 | All | All | All |
| Application | Redhat | Libvirt | 0.5.0 | All | All | All |
| Application | Redhat | Libvirt | 0.5.1 | All | All | All |
| Application | Redhat | Libvirt | 0.6.0 | All | All | All |
| Application | Redhat | Libvirt | 0.6.1 | All | All | All |
| Application | Redhat | Libvirt | 0.6.2 | All | All | All |
| Application | Redhat | Libvirt | 0.6.3 | All | All | All |
| Application | Redhat | Libvirt | 0.6.4 | All | All | All |
| Application | Redhat | Libvirt | 0.6.5 | All | All | All |
| Application | Redhat | Libvirt | 0.7.0 | All | All | All |
| Application | Redhat | Libvirt | 0.7.1 | All | All | All |
| Application | Redhat | Libvirt | 0.7.2 | All | All | All |
| Application | Redhat | Libvirt | 0.7.3 | All | All | All |
| Application | Redhat | Libvirt | 0.7.4 | All | All | All |
| Application | Redhat | Libvirt | 0.7.5 | All | All | All |
| Application | Redhat | Libvirt | 0.7.6 | All | All | All |
| Application | Redhat | Libvirt | 0.7.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.0 | All | All | All |
| Application | Redhat | Libvirt | 0.8.1 | All | All | All |
| Application | Redhat | Libvirt | 0.8.2 | All | All | All |
| Application | Redhat | Libvirt | 0.8.3 | All | All | All |
| Application | Redhat | Libvirt | 0.8.4 | All | All | All |
| Application | Redhat | Libvirt | 0.8.5 | All | All | All |
| Application | Redhat | Libvirt | 0.8.6 | All | All | All |
| Application | Redhat | Libvirt | 0.8.7 | All | All | All |
| Application | Redhat | Libvirt | 0.8.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.0 | All | All | All |
| Application | Redhat | Libvirt | 0.9.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.10 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.4 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.5 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.6 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.7 | All | All | All |
| Application | Redhat | Libvirt | 0.9.11.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.12 | All | All | All |
| Application | Redhat | Libvirt | 0.9.13 | All | All | All |
| Application | Redhat | Libvirt | 0.9.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.4 | All | All | All |
| Application | Redhat | Libvirt | 0.9.5 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.1 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.2 | All | All | All |
| Application | Redhat | Libvirt | 0.9.6.3 | All | All | All |
| Application | Redhat | Libvirt | 0.9.7 | All | All | All |
| Application | Redhat | Libvirt | 0.9.8 | All | All | All |
| Application | Redhat | Libvirt | 0.9.9 | All | All | All |
| Application | Redhat | Libvirt | 1.0.0 | All | All | All |
| Application | Redhat | Libvirt | 1.0.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.6 | All | All | All |
| Application | Redhat | Libvirt | 1.0.6 | All | All | All |
| Application | Redhat | Libvirt | 1.1.0 | All | All | All |
| Application | Redhat | Libvirt | 1.1.1 | All | All | All |
| Application | Redhat | Libvirt | 1.1.2 | All | All | All |
| Application | Redhat | Libvirt | 1.1.3 | All | All | All |
| Application | Redhat | Libvirt | 1.1.4 | All | All | All |
| Application | Redhat | Libvirt | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60895 - Gentoo update for libvirt - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| openSUSE-SU-2014:0268-1: moderate: update for libvirt | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Linux Documentation -- libvirt: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| openSUSE-SU-2014:0270-1: moderate: update for libvirt | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA56446 - Debian update for libvirt - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-2093-1: libvirt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Debian -- Security Information -- DSA-2846-1 libvirt | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 1043069 – CVE-2013-6458 libvirtd crashes when swapping disks in qemu guest multiple times - qemuMonitorJSONGetBlockStatsInfo segfault [rhel-6.6] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| libvirt: Releases | af854a3a-2127-422b-91ae-364da2661108 | libvirt.org | |
| Security Advisory SA56186 - libvirt "virDomainBlockStats()" Denial of Service Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.