CVE-2020-12430
Summary
| CVE | CVE-2020-12430 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-28 20:15:00 UTC |
| Updated | 2024-04-01 13:16:00 UTC |
| Description | An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| libvirt.org Git - libvirt.git/commit |
|
libvirt.org |
|
| [SECURITY] Fedora 31 Update: libvirt-5.6.0-7.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 1828190 – (CVE-2020-12430) CVE-2020-12430 libvirt: memory leak in domstats may allow read-only user to perform DoS attack |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Vendor Advisory |
| [SECURITY] Fedora 31 Update: libvirt-5.6.0-7.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [debian-lts-announce] 20240401 [SECURITY] [DLA 3778-1] libvirt security update |
|
lists.debian.org |
|
| libvirt.org Git - libvirt.git/commit |
MISC |
libvirt.org |
Patch, Vendor Advisory |
| USN-4371-1: libvirt vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| CVE-2020-12430 Libvirt Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Bug Access Denied |
MISC |
bugzilla.redhat.com |
Issue Tracking, Permissions Required, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 6000552 Debian Security Update for libvirt (DLA 3778-1)