Bug 1962605
| Summary: | libvirt: nodedev-list crash on host with grid host driver installed | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED DUPLICATE | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | agedosier, berrange, carnil, clalancette, eblake, jdenemar, jforbes, jsuchane, knoel, laine, libvirt-maint, mcascell, msiddiqu, pkrempa, security-response-team, veillard, virt-maint, virt-maint |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in libvirt in the virConnectListAllNodeDevices API. It only affects hosts with a PCI device and driver that supports mediated devices (ex., GRID driver). This flaw allows an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-05-20 11:24:38 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1962606 | ||
| Bug Blocks: | 1958756, 1976841 | ||
|
Description
Dhananjay Arunesh
2021-05-20 11:00:53 UTC
*** This bug has been marked as a duplicate of bug 1962306 *** I believe this CVE here (CVE-2021-3556) is just a duplicate of the CVE-2021-3559 assignment? See https://bugzilla.redhat.com/show_bug.cgi?id=1962306 which refers to CVE-2021-3559 and has as fixxing commit https://gitlab.com/libvirt/libvirt/-/commit/4c4d0e2da07b5a035b26a0ff13ec27070f7c7b1a referenced, which is the same mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=1916097. Hi Salvatore, you're right, this bug was created by mistake. Please refer to bz#1962306. Dhananjay, please mark CVE-2021-3556 as duplicate. Thank you. Hi Would it be possible to as well remove the Alias in Bugzilla for the CVE, so that people do not further stumble over it? Will the CVE as well be marked REJECTED on CNA level? Thank you for your work, Regards, Salvatore In reply to comment #4: > Hi > > Would it be possible to as well remove the Alias in Bugzilla for the CVE, so > that people do not further stumble over it? Will the CVE as well be marked > REJECTED on CNA level? Affirmative. Marked for rejection at MITRE. Bugs alias fixed. |