CVE-2021-4147: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Other sources
A flaw was found in the libvirt libxl driver. A rouge guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. See https://listman.redhat.com/archives/libvir-list/2021-November/msg00908.html.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-4147?
CVE-2021-4147 is a vulnerability in the libvirt libxl driver that could allow a malicious guest to continuously reboot itself and cause a denial of service on the host.
How severe is CVE-2021-4147?
CVE-2021-4147 has a severity rating of 6.5 out of 10.
Which software versions are affected by CVE-2021-4147?
The affected software versions of CVE-2021-4147 include libvirt versions 4.0.0-1ubuntu8.21, 6.0.0-0ubuntu8.16, 7.6.0-0ubuntu1.2, 7.10.0-2, and Redhat libvirt version 2.33.0.
How can I fix CVE-2021-4147?
To fix CVE-2021-4147, update libvirt to the recommended versions: 4.0.0-1ubuntu8.21, 6.0.0-0ubuntu8.16, 7.6.0-0ubuntu1.2, 7.10.0-2, or 2.33.0 for Redhat libvirt.
Where can I find more information about CVE-2021-4147?
You can find more information about CVE-2021-4147 in the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=2034195), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20220513-0004/), [Launchpad CVE](https://launchpad.net/bugs/cve/CVE-2021-4147).