CVE-2021-4147
published 2022-03-25CVE-2021-4147: A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting…
PriorityP422medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.23%
14.1th percentile
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 7.10.0-2 (bookworm) | libvirt 7.10.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | libvirt | < 2.33.0 | 2.33.0 |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 7.0.0-3+deb11u3 | 7.0.0-3+deb11u3 |
| redhat | libvirt | >= 0 < 7.10.0-2 | 7.10.0-2 |
| redhat | libvirt | >= 0 < 7.10.0-2 | 7.10.0-2 |
| redhat | libvirt | >= 0 < 7.10.0-2 | 7.10.0-2 |
| redhat | libvirt | >= 0 < 4.0.0-1ubuntu8.21 | 4.0.0-1ubuntu8.21 |
| redhat | libvirt | >= 0 < 6.0.0-0ubuntu8.16 | 6.0.0-0ubuntu8.16 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.7MEDIUM
vendor_redhat7.5HIGH
vendor_ubuntu6.7MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libvirt vulnerabilities
osv·2022-05-02·CVSS 6.7
CVE-2021-3667 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled certain locking
operations. A local attacker could possibly use this issue to cause libvirt
to stop accepting connections, resulting in a denial of service. This issue
only affected Ubuntu 20.04 LTS. (CVE-2021-3667)
It was discovered that libvirt incorrectly handled threads during shutdown.
A local attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-3975)
It was discovered that libvirt incorrectly handled the libxl driver. An
attacker inside a guest could possibly use this issue to cause libvirtd
to crash or stop responding, resulting in a denial of service. This issue
only affected Ubuntu 18.
GHSA
GHSA-hh52-g3xv-6xxc: A flaw was found in the libvirt libxl driver
ghsa_unreviewed·2022-03-26
CVE-2021-4147 [MEDIUM] CWE-667 GHSA-hh52-g3xv-6xxc: A flaw was found in the libvirt libxl driver
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
OSV
CVE-2021-4147: A flaw was found in the libvirt libxl driver
osv·2022-03-25·CVSS 6.5
CVE-2021-4147 [MEDIUM] CVE-2021-4147: A flaw was found in the libvirt libxl driver
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Red Hat
quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
vendor_redhat·2022-11-28·CVSS 7.5
CVE-2022-4147 [HIGH] CWE-1026 quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.
A vulnerability was found in Quarkus. The Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest have no event listeners registered on the object returned by the XMLHttpRequest upload property, and have no ReadableStream object used in the request.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2022-05-02·CVSS 6.7
CVE-2021-3631 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled certain locking
operations. A local attacker could possibly use this issue to cause libvirt
to stop accepting connections, resulting in a denial of service. This issue
only affected Ubuntu 20.04 LTS. (CVE-2021-3667)
It was discovered that libvirt incorrectly handled threads during shutdown.
A local attacker could possibly use this issue to cause libvirt to crash,
resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 20.04 LTS. (CVE-2021-3975)
It was discovered that libvirt incorrectly handled the libxl driver. An
attacker inside a guest could possibly use this issue to cause libvirtd
to crash or stop responding, resul
Red Hat
libvirt: deadlock and crash in libxl driver
vendor_redhat·2021-11-29·CVSS 6.5
CVE-2021-4147 [MEDIUM] CWE-667 libvirt: deadlock and crash in libxl driver
libvirt: deadlock and crash in libxl driver
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Statement: The versions of `libvirt` as shipped with Red Hat Enterprise Linux do not support the libxl hypervisor driver for Xen. Therefore, Red Hat Enterprise Linux is not affected by this flaw.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of us
Debian
CVE-2021-4147: libvirt - A flaw was found in the libvirt libxl driver. A malicious guest could continuous...
vendor_debian·2021·CVSS 6.5
CVE-2021-4147 [MEDIUM] CVE-2021-4147: libvirt - A flaw was found in the libvirt libxl driver. A malicious guest could continuous...
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Scope: local
bookworm: resolved (fixed in 7.10.0-2)
bullseye: resolved (fixed in 7.0.0-3+deb11u3)
forky: resolved (fixed in 7.10.0-2)
sid: resolved (fixed in 7.10.0-2)
trixie: resolved (fixed in 7.10.0-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2034195https://lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20220513-0004/https://bugzilla.redhat.com/show_bug.cgi?id=2034195https://lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20220513-0004/
2022-03-25
Published