Updated: 2025-02-10 21:28:33.228696
Description:
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | LOW | 3.5 |
CVSS Version 3.x | MEDIUM | 6.5 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
---|---|---|---|---|---|---|---|---|
CentOS 6 ELS | libvirt | 0.10.2 | 6.5 | MEDIUM | Ignored | 2022-03-31 06:48:26 | ||
CentOS 8.4 ELS | libvirt | 6.0.0-35.1 | 6.5 | MEDIUM | Released | CLSA-2022:1646071990 | 2022-03-31 06:48:26 | |
CentOS 8.5 ELS | libvirt | 6.0.0-37 | 6.5 | MEDIUM | Not Vulnerable | 2022-03-31 06:48:26 | ||
CloudLinux 6 ELS | libvirt | 0.10.2 | 6.5 | MEDIUM | Ignored | 2022-03-31 06:48:26 | ||
Oracle Linux 6 ELS | libvirt | 0.10.2 | 6.5 | MEDIUM | Ignored | 2022-03-31 06:48:26 | ||
Ubuntu 16.04 ELS | libvirt | 1.3.1-1 | 6.5 | MEDIUM | Ignored | 2022-03-31 06:48:26 | ||
Ubuntu 18.04 ELS | libvirt | 4.0.0-1 | 6.5 | MEDIUM | Not Vulnerable | 2023-07-05 05:06:47 |