CVE Vulnerabilities

CVE-2013-6436

Published: Jan 07, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.9 MODERATE
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the virsh memtune command.

Affected Software

NameVendorStart VersionEnd Version
LibvirtRedhat1.0.5 (including)1.0.5 (including)
LibvirtRedhat1.0.5.1 (including)1.0.5.1 (including)
LibvirtRedhat1.0.5.2 (including)1.0.5.2 (including)
LibvirtRedhat1.0.5.3 (including)1.0.5.3 (including)
LibvirtRedhat1.0.5.4 (including)1.0.5.4 (including)
LibvirtRedhat1.0.5.5 (including)1.0.5.5 (including)
LibvirtRedhat1.0.5.6 (including)1.0.5.6 (including)
LibvirtRedhat1.0.6 (including)1.0.6 (including)
LibvirtRedhat1.1.0 (including)1.1.0 (including)
LibvirtRedhat1.1.1 (including)1.1.1 (including)
LibvirtRedhat1.1.2 (including)1.1.2 (including)
LibvirtRedhat1.1.3 (including)1.1.3 (including)
LibvirtRedhat1.1.4 (including)1.1.4 (including)
LibvirtRedhat1.2.0 (including)1.2.0 (including)
LibvirtUbunturaring*
LibvirtUbuntusaucy*
LibvirtUbuntuupstream*

References