Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2014-3633

Published: 19 September 2014

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.

Priority

Medium

Status

Package Release Status
libvirt
Launchpad, Ubuntu, Debian
lucid Not vulnerable

precise
Released (0.9.8-2ubuntu17.20)
trusty
Released (1.2.2-0ubuntu13.1.5)
upstream Needed

Patches:
upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=3e745e8f775dfe6f64f18b5c2fe4791b35d3546b