Libvirt Security Notice: LSN-2021-0003

Denial of service by malicious guest in the libxl driver

Lifecycle

Reported on: 20211123
Published on: 20211202
Fixed on: 20211202

Credits

Reported by: Jim Fehlig
Patched by: Jim Fehlig

See also

Description

Possible deadlock when the guest is being shut down

Impact

A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.

Workaround

None.

Affected product: libvirt

Branch: master

Broken in:
Fixed in:
v8.0.0
Broken by:
Fixed by:
5c5df5310f72be4878a71ace47074c54e0d1a27d

Alternative formats: [xml] [text]