AZL-6657
Dashboard / Vulnerabilities / AZL-6657
Summary: CVE-2020-10701 affecting package libvirt for versions less than 7.10.0-1
Details: A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-10701
Affected packages
Package
Name: libvirt
Purl: pkg:rpm/azure-linux/libvirt
Affected ranges
Type: ECOSYSTEM
Events:
