CVE-2020-25637

HIGH

Description

A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

References

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00072.html

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00073.html

https://bugzilla.redhat.com/show_bug.cgi?id=1881037

Details

Source: MITRE

Published: 2020-10-06

Updated: 2020-12-04

Type: CWE-415

Risk Information

CVSS v2.0

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3.0

Base Score: 6.7

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 0.8

Severity: MEDIUM

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
147678EulerOS Virtualization 2.9.0 : libvirt (EulerOS-SA-2021-1666)NessusHuawei Local Security Checks
high
147562EulerOS Virtualization 3.0.6.6 : libvirt (EulerOS-SA-2021-1456)NessusHuawei Local Security Checks
high
147481EulerOS Virtualization 2.9.1 : libvirt (EulerOS-SA-2021-1631)NessusHuawei Local Security Checks
high
147104EulerOS Virtualization for ARM 64 3.0.6.0 : libvirt (EulerOS-SA-2021-1526)NessusHuawei Local Security Checks
high
146198Oracle Linux 7 : libvirt (ELSA-2020-5961)NessusOracle Linux Local Security Checks
high
144728EulerOS Virtualization for ARM 64 3.0.2.0 : libvirt (EulerOS-SA-2021-1045)NessusHuawei Local Security Checks
high
143884SUSE SLED15 / SLES15 Security Update : libvirt (SUSE-SU-2020:2970-1)NessusSuSE Local Security Checks
high
143851SUSE SLES12 Security Update : libvirt (SUSE-SU-2020:3143-1)NessusSuSE Local Security Checks
high
143850SUSE SLES15 Security Update : libvirt (SUSE-SU-2020:2969-1)NessusSuSE Local Security Checks
high
143827SUSE SLES12 Security Update : libvirt (SUSE-SU-2020:3038-1)NessusSuSE Local Security Checks
high
143759SUSE SLES12 Security Update : libvirt (SUSE-SU-2020:3039-1)NessusSuSE Local Security Checks
high
143649SUSE SLED15 / SLES15 Security Update : libvirt (SUSE-SU-2020:3037-1)NessusSuSE Local Security Checks
high
143635SUSE SLES12 Security Update : libvirt (SUSE-SU-2020:3095-1)NessusSuSE Local Security Checks
high
143577Amazon Linux 2 : libvirt (ALAS-2020-1569)NessusAmazon Linux Local Security Checks
high
143055CentOS 7 : libvirt (CESA-2020:5040)NessusCentOS Local Security Checks
high
142982RHEL 8 : virt:8.2 and virt-devel:8.2 (RHSA-2020:5111)NessusRed Hat Local Security Checks
high
142821Scientific Linux Security Update : libvirt on SL7.x i686/x86_64 (2020:5040)NessusScientific Linux Local Security Checks
high
142784Oracle Linux 7 : libvirt (ELSA-2020-5040)NessusOracle Linux Local Security Checks
high
142700RHEL 7 : libvirt (RHSA-2020:5040)NessusRed Hat Local Security Checks
high
142188openSUSE Security Update : libvirt (openSUSE-2020-1778)NessusSuSE Local Security Checks
high
142183openSUSE Security Update : libvirt (openSUSE-2020-1777)NessusSuSE Local Security Checks
high
141137Debian DLA-2395-1 : libvirt security updateNessusDebian Local Security Checks
high