Security Advisory

CVE-2014-8131

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-01-06 15:00:00
Last updated 2024-08-06 13:10:50
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.