Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3750

Опубликовано: 18 июл. 2023
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

Отчет

The versions of libvirt as shipped with Red Hat Enterprise Linux 6, 7, and 8 are not affected by this flaw, as they did not include the unlocking refactor that introduced the bug (upstream commit 0c4b391e2a9).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8virt:rhel/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtNot affected
Red Hat Enterprise Linux 9libvirtFixedRHSA-2023:640907.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-667
https://bugzilla.redhat.com/show_bug.cgi?id=2222210libvirt: improper locking in virStoragePoolObjListSearch may lead to denial of service

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 6.5
nvd
почти 2 года назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

CVSS3: 5.3
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
почти 2 года назад

A flaw was found in libvirt. The virStoragePoolObjListSearch function ...

suse-cvrf
почти 2 года назад

Security update for libvirt

6.5 Medium

CVSS3