CVE-2013-4399: Red Hat Libvirt

Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.

The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.

Affected products

  • Red Hat Libvirt: up to and including 1.1.3; version 0.0.1 only; version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; …

Published 2014-12-12. Last modified 2026-06-16.