UBUNTU-CVE-2021-3975
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3975
UBUNTU-CVE-2021-3975
Summary:
Details: A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
References: https://ubuntu.com/security/CVE-2021-3975, https://ubuntu.com/security/notices/USN-5399-1, https://www.cve.org/CVERecord?id=CVE-2021-3975
Affected packages
Package
Name: libvirt
Purl: pkg:deb/ubuntu/libvirt?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
