VDB

CVE-2021-3559

CVE-2021-3559 REJECTED

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.

EPSS 0.37% · 59.1th percentile

Risk Scores

EPSS Score
0.37%
59.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibvirt0, 6.0.0-0ubuntu1, 6.0.0-0ubuntu3
Ubuntu:18.04:LTSlibvirt4.0.0-1ubuntu8.12, 4.0.0-1ubuntu8.14, 4.0.0-1ubuntu8.15

Timeline

  • May 24, 2021 CVE Published
  • May 25, 2021 EPSS Score
  • Jul 27, 2021 EPSS Score
  • Sep 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 27, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 30, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 31, 2022 EPSS Score
  • Sep 30, 2022 EPSS Score
  • Dec 1, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›