Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3667

Опубликовано: 21 июл. 2021
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

Отчет

This flaw affects all versions of libvirt as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 8 Advanced Virtualization. A future update may address this issue.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtAffected
Red Hat Enterprise Linux 9libvirtNot affected
Advanced Virtualization for RHEL 8.2.1virtFixedRHSA-2021:370430.09.2021
Advanced Virtualization for RHEL 8.2.1virt-develFixedRHSA-2021:370430.09.2021
Advanced Virtualization for RHEL 8.4.0.ZvirtFixedRHSA-2021:370330.09.2021
Advanced Virtualization for RHEL 8.4.0.Zvirt-develFixedRHSA-2021:370330.09.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=1986094libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API

EPSS

Процентиль: 48%
0.00245
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
nvd
больше 3 лет назад

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.5
debian
больше 3 лет назад

An improper locking issue was found in the virStoragePoolLookupByTarge ...

suse-cvrf
больше 3 лет назад

Security update for libvirt

EPSS

Процентиль: 48%
0.00245
Низкий

6.5 Medium

CVSS3