rpm package
almalinux/libvirt-daemon-driver-storage-iscsi
pkg:rpm/almalinux/libvirt-daemon-driver-storage-iscsi
Vulnerabilities (75)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-11234 | Hig | 7.5 | < 8.0.0-23.4.module_el8.10.0+4031+06966654 | 8.0.0-23.4.module_el8.10.0+4031+06966654 | Oct 3, 2025 | A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client w | |
| CVE-2025-49133 | — | < 8.0.0-23.4.module_el8.10.0+4031+06966654 | 8.0.0-23.4.module_el8.10.0+4031+06966654 | Jun 10, 2025 | Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulner | ||
| CVE-2024-8235 | — | < 10.5.0-7.el9_5.alma.1 | 10.5.0-7.el9_5.alma.1 | Aug 30, 2024 | A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash | ||
| CVE-2024-7409 | Hig | 7.5 | < 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | Aug 5, 2024 | A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. | |
| CVE-2024-7383 | Hig | 7.4 | < 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | Aug 5, 2024 | A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic. | |
| CVE-2024-4467 | Hig | 7.8 | < 8.0.0-23.2.module_el8.10.0+3869+b8959270 | 8.0.0-23.2.module_el8.10.0+3869+b8959270 | Jul 2, 2024 | A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of | |
| CVE-2024-4418 | Med | 6.2 | < 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | May 8, 2024 | A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while | |
| CVE-2024-3446 | Hig | 8.2 | < 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | 8.0.0-23.2.module_el8.10.0+3867+f3f9981a | Apr 9, 2024 | A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU proce | |
| CVE-2024-2494 | Med | 6.2 | < 10.0.0-6.2.el9_4.alma.1 | 10.0.0-6.2.el9_4.alma.1 | Mar 21, 2024 | A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negativ | |
| CVE-2024-2496 | — | < 10.0.0-6.el9_4.alma.1 | 10.0.0-6.el9_4.alma.1 | Mar 18, 2024 | A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perfo | ||
| CVE-2024-1441 | Med | 5.5 | < 10.0.0-6.2.el9_4.alma.1 | 10.0.0-6.2.el9_4.alma.1 | Mar 11, 2024 | An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to | |
| CVE-2023-3301 | — | < 8.0.0-22.module_el8.9.0+3662+ef5fc290 | 8.0.0-22.module_el8.9.0+3662+ef5fc290 | Sep 13, 2023 | A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service. | ||
| CVE-2023-3750 | — | < 9.5.0-7.el9_3.alma.1 | 9.5.0-7.el9_3.alma.1 | Jul 24, 2023 | A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read- | ||
| CVE-2023-3354 | — | < 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma | 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma | Jul 11, 2023 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake ph | ||
| CVE-2023-2700 | — | < 9.0.0-10.2.el9_2 | 9.0.0-10.2.el9_2 | May 15, 2023 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | ||
| CVE-2023-1018 | — | < 8.0.0-19.module_el8.8.0+3553+bd08596b | 8.0.0-19.module_el8.8.0+3553+bd08596b | Feb 28, 2023 | An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM. | ||
| CVE-2022-4144 | — | < 8.0.0-10.1.module_el8.7.0+3387+571b583b | 8.0.0-10.1.module_el8.7.0+3387+571b583b | Nov 29, 2022 | An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious gue | ||
| CVE-2022-40284 | — | < 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma | 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma | Nov 6, 2022 | A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to | ||
| CVE-2022-3165 | — | < 8.0.0-19.module_el8.8.0+3553+bd08596b | 8.0.0-19.module_el8.8.0+3553+bd08596b | Oct 17, 2022 | An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service. | ||
| CVE-2022-0485 | — | < 8.0.0-5.module_el8.6.0+2880+7d9e3703 | 8.0.0-5.module_el8.6.0+2880+7d9e3703 | Aug 29, 2022 | A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the |
- affected < 8.0.0-23.4.module_el8.10.0+4031+06966654fixed 8.0.0-23.4.module_el8.10.0+4031+06966654
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client w
- CVE-2025-49133Jun 10, 2025affected < 8.0.0-23.4.module_el8.10.0+4031+06966654fixed 8.0.0-23.4.module_el8.10.0+4031+06966654
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulner
- CVE-2024-8235Aug 30, 2024affected < 10.5.0-7.el9_5.alma.1fixed 10.5.0-7.el9_5.alma.1
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent crash
- affected < 8.0.0-23.2.module_el8.10.0+3867+f3f9981afixed 8.0.0-23.2.module_el8.10.0+3867+f3f9981a
A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.
- affected < 8.0.0-23.2.module_el8.10.0+3867+f3f9981afixed 8.0.0-23.2.module_el8.10.0+3867+f3f9981a
A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD server. This issue allows a man-in-the-middle attack on NBD traffic.
- affected < 8.0.0-23.2.module_el8.10.0+3869+b8959270fixed 8.0.0-23.2.module_el8.10.0+3869+b8959270
A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices in QMP could cause the qemu-img process on the host to consume large amounts of memory or CPU time, leading to denial of
- affected < 8.0.0-23.2.module_el8.10.0+3867+f3f9981afixed 8.0.0-23.2.module_el8.10.0+3867+f3f9981a
A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while
- affected < 8.0.0-23.2.module_el8.10.0+3867+f3f9981afixed 8.0.0-23.2.module_el8.10.0+3867+f3f9981a
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU proce
- affected < 10.0.0-6.2.el9_4.alma.1fixed 10.0.0-6.2.el9_4.alma.1
A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negativ
- CVE-2024-2496Mar 18, 2024affected < 10.0.0-6.el9_4.alma.1fixed 10.0.0-6.el9_4.alma.1
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perfo
- affected < 10.0.0-6.2.el9_4.alma.1fixed 10.0.0-6.2.el9_4.alma.1
An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to
- CVE-2023-3301Sep 13, 2023affected < 8.0.0-22.module_el8.9.0+3662+ef5fc290fixed 8.0.0-22.module_el8.9.0+3662+ef5fc290
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and cause a denial of service.
- CVE-2023-3750Jul 24, 2023affected < 9.5.0-7.el9_3.alma.1fixed 9.5.0-7.el9_3.alma.1
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-
- CVE-2023-3354Jul 11, 2023affected < 8.0.0-19.2.module_el8.8.0+3585+76b9c397.almafixed 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake ph
- CVE-2023-2700May 15, 2023affected < 9.0.0-10.2.el9_2fixed 9.0.0-10.2.el9_2
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
- CVE-2023-1018Feb 28, 2023affected < 8.0.0-19.module_el8.8.0+3553+bd08596bfixed 8.0.0-19.module_el8.8.0+3553+bd08596b
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
- CVE-2022-4144Nov 29, 2022affected < 8.0.0-10.1.module_el8.7.0+3387+571b583bfixed 8.0.0-10.1.module_el8.7.0+3387+571b583b
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious gue
- CVE-2022-40284Nov 6, 2022affected < 8.0.0-19.2.module_el8.8.0+3585+76b9c397.almafixed 8.0.0-19.2.module_el8.8.0+3585+76b9c397.alma
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to
- CVE-2022-3165Oct 17, 2022affected < 8.0.0-19.module_el8.8.0+3553+bd08596bfixed 8.0.0-19.module_el8.8.0+3553+bd08596b
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.
- CVE-2022-0485Aug 29, 2022affected < 8.0.0-5.module_el8.6.0+2880+7d9e3703fixed 8.0.0-5.module_el8.6.0+2880+7d9e3703
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the
Page 1 of 4