Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gkamathe

#40771of 53,625
6.5Total CVSS
Vulnerabilities · 1
PT-2021-22700
6.5
2021-03-11
Libvirt · Libvirt · CVE-2021-3975
Name of the Vulnerable Software and Affected Versions: libvirt (affected versions not specified) Description: A use-after-free flaw was found in libvirt, where the `qemuMonitorUnregister()` function in `qemuProcessHandleMonitorEOF` is called using multiple threads without adequate protection by a monitor lock. This issue can be triggered by the `virConnectGetAllDomainStats` API when the guest is shutting down, allowing an unprivileged client with a read-only connection to perform a denial of service attack by causing the libvirt daemon to crash. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.