Memory leak in libvirt - CVE-2020-12430
Published: May 5, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the domstats command, resulting in a potential denial of service due to an error in the qemuDomainGetStatsIOThread() in qemu/qemu_driver.c in libvirt. A remote attacker can perform a denial of service attack.
Affected software
libvirt (Ubuntu package)
libvirt (Alpine package)
libvirt
Fedora
How to mitigate CVE-2020-12430
libvirt (Ubuntu package) - addressed in versions 4.0.0-1ubuntu8.17, 5.4.0-0ubuntu5.4
libvirt (Alpine package) - update to 5.5.0-r1
libvirt - update to 5.6.0-7.fc31