CVE Vulnerabilities

CVE-2014-8135

Published: Dec 19, 2014 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.1 MODERATE
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a virsh vol-upload command.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat - (including) - (including)
Libvirt Ubuntu upstream *
Libvirt Ubuntu utopic *

References