Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37726
HistoryOct 31, 2022 - 10:41 a.m.

Denial Of Service (DoS)

2022-10-3110:41:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
libvirt
denial of service
vulnerability
acl permissions
storage pool/volume apis
locked object

0.002 Low

EPSS

Percentile

61.4%

libvirt.so is vulnerable to denial of service (DoS) attacks. The locked virStoragePoolObj object in the storagePoolLookupByTargetPath function is not properly released on ACL permission failures which allows clients connected to the read-write socket with limited ACL permissions to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service conditions.

CPENameOperatorVersion
libvirt.sole0.7005.0
libvirt.sole0.7005.0