Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-3559
HistoryMay 24, 2021 - 12:15 p.m.

Command injection

2021-05-2412:15:00
PRIOn knowledge base
www.prio-n.com
3

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the ‘nodedev-list’ virsh command. The highest threat from this vulnerability is to system availability.

CPENameOperatorVersion
libvirtge6.10.0
libvirtlt7.0.0

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%