CVE-2020-25637 Details
Description
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00072.html | CVE | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00073.html | CVE | Mailing ListThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1881037 | CVE | Issue TrackingPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html | CVE | |
| https://security.gentoo.org/glsa/202210-06 | CVE | Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00072.html | [email protected] | Mailing ListThird Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00073.html | [email protected] | Mailing ListThird Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1881037 | [email protected] | Issue TrackingPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html | [email protected] | |
| https://security.gentoo.org/glsa/202210-06 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | [email protected] |
| CWE-415 | Double Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat libvirt | < 6.8.0 |
CPE
Remediation
| |
| opensuse leap | 15.1 15.2 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 1, 2024 | CVE Modified | [email protected] |
| Nov 7, 2022 | Modified Analysis | [email protected] |
| Oct 16, 2022 | CVE Modified | [email protected] |
| Sep 30, 2022 | Modified Analysis | [email protected] |
| Dec 4, 2020 | CVE Modified | [email protected] |
| Nov 2, 2020 | CVE Modified | [email protected] |
| Oct 8, 2020 | Initial Analysis | [email protected] |