An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | 4.10.0 (including) | 6.1.0 (excluding) |
Libvirt | Ubuntu | devel | * |
Libvirt | Ubuntu | eoan | * |
Libvirt | Ubuntu | focal | * |
Libvirt | Ubuntu | trusty | * |