Lucene search

K
osvGoogleOSV:CVE-2022-0897
HistoryMar 25, 2022 - 7:15 p.m.

CVE-2022-0897

2022-03-2519:15:10
Google
osv.dev
6
libvirt
nwfilter
driver
mutex
exploit
api

AI Score

6.7

Confidence

Low

EPSS

0.196

Percentile

96.4%

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt’s API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).