Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-3750

Опубликовано: 24 июл. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed9.6.0-1package
libvirtfixed9.0.0-4+deb12u1bookwormpackage
libvirtnot-affectedbullseyepackage
libvirtnot-affectedbusterpackage

Примечания

  • https://listman.redhat.com/archives/libvir-list/2023-July/240776.html

  • https://bugzilla.redhat.com/show_bug.cgi?id=2222210

  • Introduced with: https://gitlab.com/libvirt/libvirt/-/commit/0c4b391e2a90c3e0f8a8721cb539e03f14eb1d5e (v8.3.0-rc1)

  • Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/9a47442366fcf8a7b6d7422016d7bbb6764a1098 (v9.6.0-rc1)

EPSS

Процентиль: 29%
0.00106
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
redhat
около 2 лет назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
nvd
около 2 лет назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 5.3
msrc
около 1 года назад

Описание отсутствует

suse-cvrf
около 2 лет назад

Security update for libvirt

EPSS

Процентиль: 29%
0.00106
Низкий