A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI devices capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent structs g_autoptr cleanup.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | 4.5.0 (including) | 4.5.0 (including) |
Red Hat Enterprise Linux 8 | RedHat | virt-devel:rhel-8080020230612161741.63b34585 | * |
Red Hat Enterprise Linux 8 | RedHat | virt:rhel-8080020230612161741.63b34585 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | virt-devel:rhel-8060020230804183137.ad008a3a | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | virt:rhel-8060020230804183137.ad008a3a | * |
Red Hat Enterprise Linux 9 | RedHat | libvirt-0:9.0.0-10.2.el9_2 | * |
Libvirt | Ubuntu | devel | * |
Libvirt | Ubuntu | jammy | * |
Libvirt | Ubuntu | kinetic | * |
Libvirt | Ubuntu | lunar | * |
Libvirt | Ubuntu | trusty | * |
Libvirt | Ubuntu | upstream | * |
Libvirt | Ubuntu | xenial | * |