CVE-2021-4147

Related Vulnerabilities: CVE-2021-4147  

A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.

Description

A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.

Statement

The versions of `libvirt` as shipped with Red Hat Enterprise Linux do not support the libxl hypervisor driver for Xen. Therefore, Red Hat Enterprise Linux is not affected by this flaw.

The versions of libvirt as shipped with Red Hat Enterprise Linux do not support the libxl hypervisor driver for Xen. Therefore, Red Hat Enterprise Linux is not affected by this flaw.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Additional Information

  • Bugzilla 2034195: CVE-2021-4147 libvirt: deadlock and crash in libxl driver
  • CWE-667: Improper Locking
  • FAQ: Frequently asked questions about CVE-2021-4147