CVE-2020-10703
A NULL pointer dereference was found in the libvirt API that is responsible for
fetching a storage pool based on its target path. In more detail, this flaw affects
storage pools created without a target path such as network-based pools like gluster
and RBD. Unprivileged users with a read-only connection could abuse this flaw to
crash the libvirt daemon, resulting in a potential denial of service.
CVE-2020-12430
A memory leak was found in the virDomainListGetStats libvirt API that is responsible
for retrieving domain statistics when managing QEMU guests. This flaw allows
unprivileged users with a read-only connection to cause a memory leak in the domstats
command, resulting in a potential denial of service.
CVE-2020-25637
A double free memory issue was found in the libvirt API that is responsible for
requesting information about network interfaces of a running QEMU domain. This flaw
Get the latest Linux and open source security news straight to your inbox.