ALT-PU-2023-5491-3
Closed vulnerabilities
Published: 2024-04-11
Modified: 2024-11-11
Modified: 2024-11-11
BDU:2024-02835
Уязвимость функции virStoragePoolObjListSearch библиотеки управления виртуализацией Libvirt, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (5.3)Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: MEDIUM (4.9)Vector: AV:N/AC:H/Au:S/C:N/I:N/A:C
References:
Published: 2023-07-24
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-3750
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
Severity: MEDIUM (5.3)Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
References:
- https://access.redhat.com/errata/RHSA-2023:6409
- https://access.redhat.com/security/cve/CVE-2023-3750
- https://bugzilla.redhat.com/show_bug.cgi?id=2222210
- https://access.redhat.com/errata/RHSA-2023:6409
- https://access.redhat.com/security/cve/CVE-2023-3750
- https://bugzilla.redhat.com/show_bug.cgi?id=2222210
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EVK6JKP36CHE7YAFDJNPNLTW4OWJJ7TQ/
Closed bugs
После добавления модуля TPM 2.0 (TIS) виртуальная машина не запускается
