CVE-2014-8135 PUBLISHED CVSS 2.0999999046325684 LOW

The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "virsh vol-upload" command.

EPSS 0.07% · 20.7th percentile

Risk Scores

CVSS v2.0
2.0999999046325684
EPSS Score
0.07%
20.7th percentile

Affected Products

VendorProductVersions
redhatlibvirt
n/an/an/a

Timeline

References

Open in Interactive Console →