Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2020-10703
A NULL pointer dereference was found in the libvirt API that is responsible for
fetching a storage pool based on its target path. In more detail, this flaw affects
storage pools created without a target path such as network-based pools like gluster
and RBD. Unprivileged users with a read-only connection could abuse this flaw to
crash the libvirt daemon, resulting in a potential denial of service.
CVE-2020-12430
A memory leak was found in the virDomainListGetStats libvirt API that is responsible
for retrieving domain statistics when managing QEMU guests. This flaw allows
unprivileged users with a read-only connection to cause a memory leak in the domstats
command, resulting in a potential denial of service.
CVE-2020-25637
A double free memory issue was found in the libvirt API that is responsible for
requesting information about network interfaces of a running QEMU domain. This flaw
Get the latest Linux and open source security news straight to your inbox.