QID 198763

Date Published: 2022-05-04

QID 198763: Ubuntu Security Notification for libvirt Vulnerabilities (USN-5399-1)

Libvirt incorrectly handled certain lockingoperations.
Libvirt incorrectly handled threads during shutdown.
Libvirt incorrectly handled the libxl driver.
Libvirt incorrectly handled the nwfilter driver.
Libvirt incorrectly handled the polkit accesscontrol driver.
Libvirt incorrectly generated selinux labels.

A local attacker could possibly use this issue to cause libvirtto stop accepting connections, resulting in a denial of service.
A local attacker could possibly use this issue to cause libvirt to crash,resulting in a denial of service.
Anattacker inside a guest could possibly use this issue to cause libvirtdto crash or stop responding, resulting in a denial of service.
Alocal attacker could possibly use this issue to cause libvirt to crash,resulting in a denial of service.
A local attacker could possibly use this issue to causelibvirt to crash, resulting in a denial of service.
Inenvironments using selinux, this issue could allow the svirt confinementto be bypassed.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5399-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5399-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5399-1