The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
2016-04-14T15:59:01.090
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | libvirt | 1.2.14 | Yes |
Application | redhat | libvirt | 1.2.15 | Yes |
Application | redhat | libvirt | 1.2.16 | Yes |
Application | redhat | libvirt | 1.2.17 | Yes |
Application | redhat | libvirt | 1.2.18 | Yes |
Application | redhat | libvirt | 1.2.19 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.04 | Yes |
Operating System | canonical | ubuntu_linux | 15.10 | Yes |