Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-12430

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak in the domstats command, resulting in a potential denial of service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
References
Products affected by CVE-2020-12430
  • Redhat » Libvirt » Version: 4.10.0
    cpe:2.3:a:redhat:libvirt:4.10.0
  • Redhat » Libvirt » Version: 5.0.0
    cpe:2.3:a:redhat:libvirt:5.0.0
  • Redhat » Libvirt » Version: 5.1.0
    cpe:2.3:a:redhat:libvirt:5.1.0
  • Redhat » Libvirt » Version: 5.10.0
    cpe:2.3:a:redhat:libvirt:5.10.0
  • Redhat » Libvirt » Version: 5.2.0
    cpe:2.3:a:redhat:libvirt:5.2.0
  • Redhat » Libvirt » Version: 5.3.0
    cpe:2.3:a:redhat:libvirt:5.3.0
  • Redhat » Libvirt » Version: 5.4.0
    cpe:2.3:a:redhat:libvirt:5.4.0
  • Redhat » Libvirt » Version: 5.5.0
    cpe:2.3:a:redhat:libvirt:5.5.0
  • Redhat » Libvirt » Version: 5.6.0
    cpe:2.3:a:redhat:libvirt:5.6.0
  • Redhat » Libvirt » Version: 5.7.0
    cpe:2.3:a:redhat:libvirt:5.7.0
  • Redhat » Libvirt » Version: 5.8.0
    cpe:2.3:a:redhat:libvirt:5.8.0
  • Redhat » Libvirt » Version: 5.9.0
    cpe:2.3:a:redhat:libvirt:5.9.0
  • Redhat » Libvirt » Version: 6.0.0
    cpe:2.3:a:redhat:libvirt:6.0.0
  • Redhat » Enterprise Linux » Version: 8.0
    cpe:2.3:o:redhat:enterprise_linux:8.0


Contact Us

Shodan ® - All rights reserved