CVE-2023-2700

NameCVE-2023-2700
DescriptionA vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1036297

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libvirt (PTS)jessie, jessie (lts)1.2.9-9+deb8u8fixed
stretch (security)3.0.0-4+deb9u5fixed
stretch (lts), stretch3.0.0-4+deb9u6fixed
buster (security), buster, buster (lts)5.0.0-4+deb10u2fixed
bullseye7.0.0-3+deb11u3fixed
bookworm9.0.0-4+deb12u2fixed
sid, trixie10.9.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libvirtsourceexperimental9.3.0-1
libvirtsourcejessie(not affected)
libvirtsourcestretch(not affected)
libvirtsourcebuster(not affected)
libvirtsourcebullseye(not affected)
libvirtsource(unstable)9.0.0-41036297

Notes

[bullseye] - libvirt <not-affected> (Vulnerable code not present)
[buster] - libvirt <not-affected> (Vulnerable code not present)
https://bugzilla.redhat.com/show_bug.cgi?id=2203653
Introduced in: https://gitlab.com/libvirt/libvirt/-/commit/c97518d9b833a607f29b9bb02e3fbe74c011c088 (v7.7.0-rc1)
Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/6425a311b8ad19d6f9c0b315bf1d722551ea3585 (v9.3.0)
[stretch] - libvirt <not-affected> (Vulnerable code introduced later)
[jessie] - libvirt <not-affected> (Vulnerable code introduced later)

Search for package or bug name: Reporting problems