CVE-2013-6458

Source
https://nvd.nist.gov/vuln/detail/CVE-2013-6458
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2013-6458.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2013-6458
Downstream
Related
Published
2014-01-24T18:55:04Z
Modified
2025-08-09T19:01:27Z
Summary
[none]
Details

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

References

Affected packages