Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0897

Опубликовано: 17 мар. 2022
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

Отчет

A future update may address this issue in Red Hat Enterprise Linux 8 and RHEL Advanced Virtualization.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtFix deferred
Red Hat Enterprise Linux 8virt-develFixedRHSA-2022:747208.11.2022
Red Hat Enterprise Linux 8virtFixedRHSA-2022:747208.11.2022
Red Hat Enterprise Linux 9libvirtFixedRHSA-2022:800315.11.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=2063883libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service

EPSS

Процентиль: 13%
0.00045
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
nvd
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
debian
около 3 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjLis ...

suse-cvrf
почти 2 года назад

Security update for libvirt

suse-cvrf
около 3 лет назад

Security update for libvirt

EPSS

Процентиль: 13%
0.00045
Низкий

5 Medium

CVSS3