Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2023-3750

Published: 19 July 2023

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

Notes

AuthorNote
mdeslaur
only affects libvirt 8.3.0 and newer

Priority

Medium

Cvss 3 Severity Score

5.3

Score breakdown

Status

Package Release Status
libvirt
Launchpad, Ubuntu, Debian
bionic Not vulnerable

focal Not vulnerable
(6.0.0-0ubuntu8.16)
jammy Not vulnerable
(8.0.0-1ubuntu7.6)
kinetic Ignored
(end of life)
lunar
Released (9.0.0-2ubuntu1.2)
trusty Not vulnerable

upstream Needs triage

xenial Not vulnerable

Patches:
upstream: https://gitlab.com/libvirt/libvirt/-/commit/9a47442366fcf8a7b6d7422016d7bbb6764a1098

Severity score breakdown

Parameter Value
Base score 5.3
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H