CVE-2013-6436

low
Published 2014-01-07 · Modified 2026-04-29
CVSS v3
VIR risk
2.1

Description

The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) via a guest in the shutdown status, as demonstrated by the "virsh memtune" command.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.2.0-1
debian debianbullseyefixed1.2.0-1
debian debianforkyfixed1.2.0-1
debian debiansidfixed1.2.0-1
debian debiantrixiefixed1.2.0-1

Application impact

VendorProductVersionsFixed
redhat redhatlibvirt1.0.5
redhat redhatlibvirt1.0.5.1
redhat redhatlibvirt1.0.5.2
redhat redhatlibvirt1.0.5.3
redhat redhatlibvirt1.0.5.4
redhat redhatlibvirt1.0.5.5
redhat redhatlibvirt1.0.5.6
redhat redhatlibvirt1.0.6
redhat redhatlibvirt1.1.0
redhat redhatlibvirt1.1.1
redhat redhatlibvirt1.1.2
redhat redhatlibvirt1.1.3
redhat redhatlibvirt1.1.4
redhat redhatlibvirt1.2.0

References

CWEs

CWE-264

💬 Discuss CVE-2013-6436 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.