Resource management error in libvirt - CVE-2020-10703
Published: May 23, 2020
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources with the application when performing pool lookups within the storagePoolLookupByTargetPath() function in storage/storage_driver.c. A remote user can create a pool with empty target path and then perform search for an empty target, which results in libvirt crash.
Affected software
libvirt (Ubuntu package)
libvirt (Red Hat package)
libvirt
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Fedora
How to mitigate CVE-2020-10703
libvirt (Ubuntu package) - addressed in versions 4.0.0-1ubuntu8.17, 5.4.0-0ubuntu5.4
libvirt (Red Hat package) - update to 4.5.0-36.el7
libvirt - update to 5.6.0-7.fc31