CVE-2022-0897
Vulnerability Summary
Timeline
Description
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- v2.0•MEDIUM•Score: 4AV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 1.05%• Percentile: 63%
Techniques & Countermeasures
- CWE-667•Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
Affected Systems
- debian•libvirt
< 7.0.0-3+deb11u3 | < 8.2.0-1 | < 8.2.0-1 | < 8.2.0-1
- ubuntu•libvirt
< 4.0.0-1ubuntu8.21 | < 6.0.0-0ubuntu8.16 | < 8.0.0-1ubuntu7.5
- netapp•ontap_select_deploy_administration_utility
na
- redhat•libvirt
≤ 1.1.1
References (8)
- https://bugzilla.redhat.com/show_bug.cgi?id=2063883
- https://security.gentoo.org/glsa/202210-06
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://security-tracker.debian.org/tracker/CVE-2022-0897
- https://ubuntu.com/security/CVE-2022-0897
- https://ubuntu.com/security/notices/USN-5399-1
- https://ubuntu.com/security/notices/USN-6126-1
- https://www.cve.org/CVERecord?id=CVE-2022-0897