First published: Mon Dec 20 2021(Updated: )
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libvirt | <2.33.0 | 2.33.0 |
debian/libvirt | 7.0.0-3+deb11u3 9.0.0-4+deb12u1 10.7.0-3 | |
LibVIRT | <2.33.0 | |
Fedoraproject Fedora | =35 | |
NetApp ONTAP Select Deploy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4147 is a vulnerability in the libvirt libxl driver that could allow a malicious guest to continuously reboot itself and cause a denial of service on the host.
CVE-2021-4147 has a severity rating of 6.5 out of 10.
The affected software versions of CVE-2021-4147 include libvirt versions 4.0.0-1ubuntu8.21, 6.0.0-0ubuntu8.16, 7.6.0-0ubuntu1.2, 7.10.0-2, and Redhat libvirt version 2.33.0.
To fix CVE-2021-4147, update libvirt to the recommended versions: 4.0.0-1ubuntu8.21, 6.0.0-0ubuntu8.16, 7.6.0-0ubuntu1.2, 7.10.0-2, or 2.33.0 for Redhat libvirt.
You can find more information about CVE-2021-4147 in the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=2034195), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20220513-0004/), [Launchpad CVE](https://launchpad.net/bugs/cve/CVE-2021-4147).