CVE-2014-1447

Publication date 24 January 2014

Last updated 24 July 2024


Ubuntu priority

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

Read the notes from the security team

Status

Package Ubuntu Release Status
libvirt 13.10 saucy
Fixed 1.1.1-0ubuntu8.5
13.04 raring Ignored end of life
12.10 quantal
Fixed 0.9.13-0ubuntu12.6
12.04 LTS precise
Fixed 0.9.8-2ubuntu17.17
10.04 LTS lucid
Not affected

Notes


jdstrand

per upstream, introduced in 0.9.8

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libvirt