CVE-2021-3667

    Dashboard / Vulnerabilities / CVE-2021-3667

    CVE-2021-3667

    Published: 2 Mar 2022Last Modified: 9 Jul 2026

    Summary:

    Details: An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 6b59754bfda9477586a75af0c0b9ce1036c414e8
    Fixed -None

    Affected versions

    v7.5.0
    v7.5.0-rc2
    v7.5.0-rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2021-3667 | CVE-DB