CVE-2021-3975
published 2022-08-23CVE-2021-3975: A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.22%
65.0th percentile
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 7.6.0-1 (bookworm) | libvirt 7.6.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cm1_libvirt_6.1.0-6_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_for_power_little_endian_eus | — | — |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | libvirt | < 7.1.0 | 7.1.0 |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 7.0.0-3+deb11u3 | 7.0.0-3+deb11u3 |
| redhat | libvirt | >= 0 < 7.6.0-1 | 7.6.0-1 |
| redhat | libvirt | >= 0 < 7.6.0-1 | 7.6.0-1 |
| redhat | libvirt | >= 0 < 7.6.0-1 | 7.6.0-1 |
| redhat | libvirt | >= 0 < 4.0.0-1ubuntu8.21 | 4.0.0-1ubuntu8.21 |
| redhat | libvirt | >= 0 < 6.0.0-0ubuntu8.16 | 6.0.0-0ubuntu8.16 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.7MEDIUM
vendor_ubuntu6.7MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. T
vendor_msrc·2022-08-09·CVSS 6.5
CVE-2021-3975 [MEDIUM] CWE-416 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. T
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2022-05-02·CVSS 6.7
CVE-2021-3631 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled certain locking
operations. A local attacker could possibly use this issue to cause libvirt
to stop accepting connections, resulting in a denial of service. This issue
only affected Ubuntu 20.04 LTS. (CVE-2021-3667)
It was discovered that libvirt incorrectly handled threads during shutdown.
A local attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-3975)
It was discovered that libvirt incorrectly handled the libxl driver. An
attacker inside a guest could possibly use this issue to cause libvirtd
to crash or stop responding, resul
Red Hat
libvirt: segmentation fault during VM shutdown can lead to vdsm hang
vendor_redhat·2021-11-17·CVSS 6.5
CVE-2021-3975 [MEDIUM] CWE-416 libvirt: segmentation fault during VM shutdown can lead to vdsm hang
libvirt: segmentation fault during VM shutdown can lead to vdsm hang
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the gues
Debian
CVE-2021-3975: libvirt - A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function...
vendor_debian·2021·CVSS 6.5
CVE-2021-3975 [MEDIUM] CVE-2021-3975: libvirt - A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function...
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Scope: local
bookworm: resolved (fixed in 7.6.0-1)
bullseye: resolved (fixed in 7.0.0-3+deb11u3)
forky: resolved (fixed in 7.6.0-1)
sid: resolved (fixed in 7.6.0-1)
trixie: resolved (fixed in 7.6.0-1)
GHSA
GHSA-pg89-46xq-98vv: A use-after-free flaw was found in libvirt
ghsa_unreviewed·2022-08-24
CVE-2021-3975 [MEDIUM] CWE-416 GHSA-pg89-46xq-98vv: A use-after-free flaw was found in libvirt
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
OSV
CVE-2021-3975: A use-after-free flaw was found in libvirt
osv·2022-08-23·CVSS 6.5
CVE-2021-3975 [MEDIUM] CVE-2021-3975: A use-after-free flaw was found in libvirt
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
OSV
libvirt vulnerabilities
osv·2022-05-02·CVSS 6.7
CVE-2021-3667 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled certain locking
operations. A local attacker could possibly use this issue to cause libvirt
to stop accepting connections, resulting in a denial of service. This issue
only affected Ubuntu 20.04 LTS. (CVE-2021-3667)
It was discovered that libvirt incorrectly handled threads during shutdown.
A local attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-3975)
It was discovered that libvirt incorrectly handled the libxl driver. An
attacker inside a guest could possibly use this issue to cause libvirtd
to crash or stop responding, resulting in a denial of service. This issue
only affected Ubuntu 18.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3975https://bugzilla.redhat.com/show_bug.cgi?id=2024326https://github.com/libvirt/libvirt/commit/1ac703a7d0789e46833f4013a3876c2e3af18ec7https://lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20221201-0002/https://ubuntu.com/security/CVE-2021-3975https://access.redhat.com/security/cve/CVE-2021-3975https://bugzilla.redhat.com/show_bug.cgi?id=2024326https://github.com/libvirt/libvirt/commit/1ac703a7d0789e46833f4013a3876c2e3af18ec7https://lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20221201-0002/https://ubuntu.com/security/CVE-2021-3975
2022-08-23
Published