A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a denial of service.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | * | 5.0.0 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | libvirt-0:4.5.0-23.el7 | * |
Libvirt | Ubuntu | bionic | * |
Libvirt | Ubuntu | cosmic | * |
Libvirt | Ubuntu | upstream | * |
Libvirt | Ubuntu | xenial | * |