<security-notice xmlns="http://security.libvirt.org/xmlns/security-notice/1.0">
  <id>2021-0002</id>

  <summary>improper locking on ACL failure in virStoragePoolLookupByTargetPath API</summary>

  <description>
<![CDATA[The error path on ACL failure did not release the lock on the storage pool object.]]>
  </description>

  <impact>
<![CDATA[When using ACLs, a user with no permission to access the pool could deny others
         from accessing the storage pool object.]]>
  </impact>

  <workaround>
<![CDATA[Deny the user access to the virStoragePoolLookupByTargetPath API.]]>
  </workaround>

  <credits>
    <reporter>
      <name>Yan Fu</name>
      <email>yafu@redhat.com</email>
    </reporter>
    <patcher>
      <name>Peter Krempa</name>
      <email>pkrempa@redhat.com</email>
    </patcher>
  </credits>

  <lifecycle>
    <reported>20210721</reported>
    <published>20210721</published>
    <fixed>20210723</fixed>
  </lifecycle>

  <reference>
    <advisory type="CVE" id="2021-3667"/>
    <bug tracker="redhat" id="1984318"/>
  </reference>

  <product name="libvirt">
    <repository>libvirt.git</repository>
    <branch>
      <name>master</name>
      <tag state="vulnerable">v4.1.0</tag>
      <tag state="vulnerable">v4.2.0</tag>
      <tag state="vulnerable">v4.3.0</tag>
      <tag state="vulnerable">v4.4.0</tag>
      <tag state="vulnerable">v4.5.0</tag>
      <tag state="vulnerable">v4.6.0</tag>
      <tag state="vulnerable">v4.7.0</tag>
      <tag state="vulnerable">v4.8.0</tag>
      <tag state="vulnerable">v4.9.0</tag>
      <tag state="vulnerable">v4.10.0</tag>
      <tag state="vulnerable">v5.0.0</tag>
      <tag state="vulnerable">v5.1.0</tag>
      <tag state="vulnerable">v5.2.0</tag>
      <tag state="vulnerable">v5.3.0</tag>
      <tag state="vulnerable">v5.4.0</tag>
      <tag state="vulnerable">v5.5.0</tag>
      <tag state="vulnerable">v5.6.0</tag>
      <tag state="vulnerable">v5.7.0</tag>
      <tag state="vulnerable">v5.8.0</tag>
      <tag state="vulnerable">v5.9.0</tag>
      <tag state="vulnerable">v5.10.0</tag>
      <tag state="vulnerable">v6.0.0</tag>
      <tag state="vulnerable">v6.1.0</tag>
      <tag state="vulnerable">v6.2.0</tag>
      <tag state="vulnerable">v6.3.0</tag>
      <tag state="vulnerable">v6.4.0</tag>
      <tag state="vulnerable">v6.5.0</tag>
      <tag state="vulnerable">v6.6.0</tag>
      <tag state="vulnerable">v6.7.0</tag>
      <tag state="vulnerable">v6.8.0</tag>
      <tag state="vulnerable">v6.9.0</tag>
      <tag state="vulnerable">v6.10.0</tag>
      <tag state="vulnerable">v7.0.0</tag>
      <tag state="vulnerable">v7.1.0</tag>
      <tag state="vulnerable">v7.2.0</tag>
      <tag state="vulnerable">v7.3.0</tag>
      <tag state="vulnerable">v7.4.0</tag>
      <tag state="vulnerable">v7.5.0</tag>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
      <tag state="fixed">v7.6.0</tag>
      <change state="fixed">447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87</change>
    </branch>
    <branch>
      <name>v4.1-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.2-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.3-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.4-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.5-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.6-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.7-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.8-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.9-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v4.10-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v5.0-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v5.1-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v5.1.0-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v5.2-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
    <branch>
      <name>v5.3-maint</name>
      <change state="vulnerable">7aa0e8c0cb8a6293d0c6f7e3d29c13b96dec2129</change>
    </branch>
  </product>

</security-notice>
