REDHAT-BUG-1986094: Low severity oracle libvirt vulnerability
A flaw was found in the libvirt virStoragePoolLookupByTargetPath API. The storagePoolLookupByTargetPath() function does not properly release a locked object (virStoragePoolObj) on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition.
Upstream fix: https://libvirt.org/git/?p=libvirt.git;a=commit;h=447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1986094?
The severity of REDHAT-BUG-1986094 is moderate due to its potential impact on access control.
How do I fix REDHAT-BUG-1986094?
To fix REDHAT-BUG-1986094, apply the latest patches released for libvirt that address this vulnerability.
What is the impact of REDHAT-BUG-1986094?
The impact of REDHAT-BUG-1986094 allows clients with limited ACL permissions to exploit a flaw in the virStoragePoolLookupByTargetPath API.
Who is affected by REDHAT-BUG-1986094?
Users and applications utilizing the libvirt API for storage pool management may be affected by REDHAT-BUG-1986094.
Is there a workaround for REDHAT-BUG-1986094?
Currently, there are no known workarounds for REDHAT-BUG-1986094 other than applying the appropriate security patches.