An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3778-1 | libvirt security update |
Ubuntu USN |
USN-4371-1 | libvirt vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:56:52.057Z
Reserved: 2020-04-28T00:00:00
Link: CVE-2020-12430
No data.
Status : Modified
Published: 2020-04-28T20:15:12.717
Modified: 2024-11-21T04:59:42.750
Link: CVE-2020-12430
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN