Libvirt Security Notice: LSN-2023-0001 ====================================== Summary: race condition leading to a crash in 'virStoragePoolObjListSearch' Reported on: 20230711 Published on: 20230720 Fixed on: 20230720 Reported by: Han Han Patched by: Peter Krempa See also: CVE-2023-3750 Description ----------- Refactor of locking in 'virStoragePoolObjListSearch' caused the callers to access storage pool objects without holding a corresponding lock. In cases when the object would be at the same time modified by another thread this could lead to a crash. Impact ------ Unprivileged users using the read-only connection may crash the libvirt daemon. Workaround ---------- None Affected product ---------------- Name: libvirt Repository: https://gitlab.com/libvirt/libvirt Branch: master Broken in: v8.3.0 Broken in: v8.4.0 Broken in: v8.5.0 Broken in: v8.6.0 Broken in: v8.7.0 Broken in: v8.8.0 Broken in: v8.9.0 Broken in: v8.10.0 Broken in: v9.0.0 Broken in: v9.1.0 Broken in: v9.2.0 Broken in: v9.3.0 Broken in: v9.4.0 Broken in: v9.5.0 Fixed in: v9.6.0 Broken by: 0c4b391e2a9 Fixed by: 9a47442366fcf8a7b6d7422016d7bbb6764a1098