CVE Vulnerabilities

CVE-2013-4153

Published: Sep 30, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
6.8 IMPORTANT
AV:A/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM

Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the virsh vcpucount dom –guest command.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat 1.0.6 (including) 1.0.6 (including)
Libvirt Redhat 1.1.0 (including) 1.1.0 (including)
Libvirt Ubuntu upstream *

References