UBUNTU-CVE-2021-3667
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3667
UBUNTU-CVE-2021-3667
Summary:
Details: An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-3667, https://ubuntu.com/security/notices/USN-5399-1, https://www.cve.org/CVERecord?id=CVE-2021-3667
Affected packages
Package
Name: libvirt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
