Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-3975
HistoryNov 24, 2021 - 12:00 a.m.

CVE-2021-3975

2021-11-2400:00:00
ubuntu.com
ubuntu.com
19

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%

A use-after-free flaw was found in libvirt. The qemuMonitorUnregister()
function in qemuProcessHandleMonitorEOF is called using multiple threads
without being adequately protected by a monitor lock. This flaw could be
triggered by the virConnectGetAllDomainStats API when the guest is shutting
down. An unprivileged client with a read-only connection could use this
flaw to perform a denial of service attack by causing the libvirt daemon to
crash.

Bugs

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%