Bug 910862 (CVE-2014-8136) - VUL-0: CVE-2014-8136: libvirt: local denial of service in qemu/qemu_driver.c
Summary: VUL-0: CVE-2014-8136: libvirt: local denial of service in qemu/qemu_driver.c
Status: RESOLVED FIXED
Alias: CVE-2014-8136
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/111740/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-19 16:55 UTC by Alexander Bergmann
Modified: 2016-04-27 19:33 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-12-19 16:55:27 UTC
rh#1176176

Common Vulnerabilities and Exposures assigned an identifier CVE-2014-8136 to
the following vulnerability:

Name: CVE-2014-8136
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8136
Assigned: 20141010
Reference: http://secunia.com/advisories/61111

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2
functions in qemu/qemu_driver.c in libvirt do not unlock the domain
when an ACL check fails, which allow local users to cause a denial of
service via unspecified vectors.

Upstream commit that addresses this:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=2bdcd29c713dfedd813c89f56ae98f6f3898313d

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1176176
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8136
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8136
Comment 1 Swamp Workflow Management 2014-12-19 23:01:02 UTC
bugbot adjusting priority
Comment 2 James Fehlig 2014-12-20 00:00:29 UTC
Affects openSUSE13.1, openSUSE13.2, and SLE12.  Factory is fixed by the update to libvirt 1.2.11.
Comment 3 James Fehlig 2014-12-22 05:14:44 UTC
I've submitted a libvirt package containing the fix for openSUSE13.1 (MR#266111) and openSUSE13.2 (MR#266112).  Fix for SLE12 is queued in Devel:Virt:SLE-12/libvirt, but there is already a running update for SLE12.  Security, do you want me to resubmit for SLE12, or defer this until the next update?
Comment 4 Bernhard Wiedemann 2014-12-22 06:00:39 UTC
This is an autogenerated message for OBS integration:
This bug (910862) was mentioned in
https://build.opensuse.org/request/show/266111 13.1 / libvirt
Comment 5 Marcus Meissner 2014-12-22 20:06:20 UTC
QA has not started in SLE12, so you can do a incremental submit and we can merge it.
Comment 7 James Fehlig 2014-12-23 00:07:29 UTC
Thanks Marcus.  Submitted MR#47743 to SUSE:SLE-12:Update.  Handing bug over to security-team.
Comment 8 Swamp Workflow Management 2015-01-02 09:08:34 UTC
openSUSE-SU-2015:0006-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 910862
CVE References: CVE-2014-8136
Sources used:
openSUSE 13.1 (src):    libvirt-1.1.2-2.44.1
Comment 9 Swamp Workflow Management 2015-01-02 09:09:37 UTC
openSUSE-SU-2015:0008-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 904432,909274,910860,910862
CVE References: CVE-2014-8131,CVE-2014-8135,CVE-2014-8136
Sources used:
openSUSE 13.2 (src):    libvirt-1.2.9-8.1
Comment 10 Marcus Meissner 2015-02-09 14:12:27 UTC
releasedc
Comment 11 Swamp Workflow Management 2015-02-09 15:10:17 UTC
SUSE-SU-2015:0241-1: An update that solves three vulnerabilities and has 9 fixes is now available.

Category: security (moderate)
Bug References: 891936,899334,899484,900587,902976,903756,904176,904426,904432,909828,910862,911737
CVE References: CVE-2014-3657,CVE-2014-7823,CVE-2014-8136
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    libvirt-1.2.5-21.1
SUSE Linux Enterprise Software Development Kit 12 (src):    libvirt-1.2.5-21.1
SUSE Linux Enterprise Server 12 (src):    libvirt-1.2.5-21.1
SUSE Linux Enterprise Desktop 12 (src):    libvirt-1.2.5-21.1