The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mageia | Mageia | 4.0 (including) | 4.0 (including) |
Red Hat Enterprise Linux 7 | RedHat | libvirt-0:1.2.8-16.el7 | * |
Red Hat Gluster Storage 3.1 for RHEL 7 | RedHat | libvirt-0:1.2.8-16.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | libvirt-0:1.2.8-16.el7 | * |
Libvirt | Ubuntu | lucid | * |
Libvirt | Ubuntu | trusty | * |
Libvirt | Ubuntu | upstream | * |
Libvirt | Ubuntu | utopic | * |