CVE-2013-4153
Publication date 30 September 2013
Last updated 24 July 2024
Ubuntu priority
Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the "virsh vcpucount dom --guest" command.
Status
Package | Ubuntu Release | Status |
---|---|---|
libvirt | ||
Notes
mdeslaur
Introduced by: http://libvirt.org/git/?p=libvirt.git;a=commit;h=3099c063e348fdc79a900f88bcfc5389dada7786 which is in 1.1.0
Patch details
Package | Patch details |
---|---|
libvirt |