First published: Wed May 19 2021(Updated: )
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | >=6.10.0<7.0.0 | |
NetApp ONTAP Select Deploy administration utility | ||
redhat/libvirt | <7.0.0 | 7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw in libvirt is CVE-2021-3559.
The affected software includes Redhat Libvirt and NetApp ONTAP Select Deploy administration utility.
The severity of CVE-2021-3559 is medium (CVSS score: 6.5).
CVE-2021-3559 only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver).
An unprivileged client with a read-only connection can use CVE-2021-3559 to crash the libvirt daemon.