Back

MEDIUM

Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service

Published Jul 24, 2023

Description

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

Affected products

Remediation

Red Hat statement

The versions of `libvirt` as shipped with Red Hat Enterprise Linux 6, 7, and 8 are not affected by this flaw, as they did not include the unlocking refactor that introduced the bug (upstream commit 0c4b391e2a9).

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jul 24, 2023
Updated Nov 8, 2025
Reserved Jul 18, 2023

CISA Vulnrichment

Updated Feb 12, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 18, 2023
Bugzilla 2222210

ENISA EUVD

Assigner redhat
Published Jul 24, 2023
Updated Nov 8, 2025

GitHub

No data