{"schema_version":"1.7.5","id":"CVE-2021-3667","published":"2022-03-02T23:15:08.843Z","modified":"2026-07-09T05:44:43.770292Z","related":["ALSA-2021:4191","SUSE-SU-2021:2812-1","SUSE-SU-2021:3277-1","SUSE-SU-2021:3540-1","SUSE-SU-2021:3586-1","openSUSE-SU-2021:1451-1","openSUSE-SU-2021:2812-1","openSUSE-SU-2024:11008-1"],"details":"An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvirt/libvirt","events":[{"introduced":"6b59754bfda9477586a75af0c0b9ce1036c414e8"},{"last_affected":"03eadc86fc5cdadbc4ab18123d820b6e4e321abd"}],"database_specific":{"cpe":"cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.0"},{"last_affected":"7.5.0"}],"source":"CPE_RANGE"}}],"versions":["v7.5.0","CVE-2021-3631","v7.5.0-rc2","v7.5.0-rc1","v7.4.0","v7.4.0-rc2","v7.4.0-rc1","v7.3.0","v7.3.0-rc2","v7.3.0-rc1","v7.2.0","v7.2.0-rc2","v7.2.0-rc1","v7.1.0","v7.1.0-rc2","v7.1.0-rc1","v7.0.0","v7.0.0-rc2","v7.0.0-rc1","v6.10.0","v6.10.0-rc2","v6.10.0-rc1","v6.9.0","v6.9.0-rc2","v6.9.0-rc1","v6.8.0","CVE-2020-25637","v6.8.0-rc2","v6.8.0-rc1","v6.7.0","v6.7.0-rc2","v6.7.0-rc1","v6.6.0","CVE-2020-14339","v6.6.0-rc1","v6.5.0","v6.5.0-rc2","v6.5.0-rc1","v6.4.0","v6.4.0-rc1","v6.3.0","v6.3.0-rc1","v6.2.0","v6.2.0-rc1","v6.1.0","v6.1.0-rc2","v6.1.0-rc1","v6.0.0","v6.0.0-rc2","v6.0.0-rc1","v5.10.0","v5.10.0-rc2","v5.10.0-rc1","v5.9.0","v5.9.0-rc1","v5.8.0","v5.8.0-rc2","v5.8.0-rc1","v5.7.0","v5.7.0-rc2","v5.7.0-rc1","v5.6.0","v5.6.0-rc2","v5.6.0-rc1","v5.5.0","v5.5.0-rc2","v5.5.0-rc1","CVE-2019-10168","CVE-2019-10161","CVE-2019-10166","CVE-2019-10167","v5.4.0","v5.4.0-rc2","v5.4.0-rc1","v4.2.0","v4.3.0","v4.4.0","v4.6.0","v4.8.0","v4.9.0","v4.10.0","v5.0.0","v5.2.0","CVE-2019-10132","v5.3.0","v4.7.0","v5.3.0-rc2","v5.3.0-rc1","CVE-2019-3886","v5.2.0-rc2","v5.2.0-rc1","v5.1.0","v5.1.0-rc2","v5.1.0-rc1","v5.0.0-rc2","v5.0.0-rc1","v4.10.0-rc2","v4.10.0-rc1","v4.9.0-rc1","v4.8.0-rc2","v4.8.0-rc1","v4.7.0-rc2","v4.7.0-rc1","v4.6.0-rc2","v4.6.0-rc1","v4.5.0","v4.5.0-rc2","v4.5.0-rc1","v4.4.0-rc2","v4.4.0-rc1","v4.1.0","v4.3.0-rc2","v4.3.0-rc1","v4.2.0-rc2","v4.2.0-rc1","CVE-2018-1064"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3667.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libvirt/libvirt","events":[{"introduced":"6b59754bfda9477586a75af0c0b9ce1036c414e8"},{"last_affected":"03eadc86fc5cdadbc4ab18123d820b6e4e321abd"},{"fixed":"447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87"}],"database_specific":{"cpe":"cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.0"},{"last_affected":"7.5.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v7.5.0","CVE-2021-3631","v7.5.0-rc2","v7.5.0-rc1","v7.4.0","v7.4.0-rc2","v7.4.0-rc1","v7.3.0","v7.3.0-rc2","v7.3.0-rc1","v7.2.0","v7.2.0-rc2","v7.2.0-rc1","v7.1.0","v7.1.0-rc2","v7.1.0-rc1","v7.0.0","v7.0.0-rc2","v7.0.0-rc1","v6.10.0","v6.10.0-rc2","v6.10.0-rc1","v6.9.0","v6.9.0-rc2","v6.9.0-rc1","v6.8.0","CVE-2020-25637","v6.8.0-rc2","v6.8.0-rc1","v6.7.0","v6.7.0-rc2","v6.7.0-rc1","v6.6.0","CVE-2020-14339","v6.6.0-rc1","v6.5.0","v6.5.0-rc2","v6.5.0-rc1","v6.4.0","v6.4.0-rc1","v6.3.0","v6.3.0-rc1","v6.2.0","v6.2.0-rc1","v6.1.0","v6.1.0-rc2","v6.1.0-rc1","v6.0.0","v6.0.0-rc2","v6.0.0-rc1","v5.10.0","v5.10.0-rc2","v5.10.0-rc1","v5.9.0","v5.9.0-rc1","v5.8.0","v5.8.0-rc2","v5.8.0-rc1","v5.7.0","v5.7.0-rc2","v5.7.0-rc1","v5.6.0","v5.6.0-rc2","v5.6.0-rc1","v5.5.0","v5.5.0-rc2","v5.5.0-rc1","CVE-2019-10168","CVE-2019-10161","CVE-2019-10166","CVE-2019-10167","v5.4.0","v5.4.0-rc2","v5.4.0-rc1","v4.2.0","v4.3.0","v4.4.0","v4.6.0","v4.8.0","v4.9.0","v4.10.0","v5.0.0","v5.2.0","CVE-2019-10132","v5.3.0","v4.7.0","v5.3.0-rc2","v5.3.0-rc1","CVE-2019-3886","v5.2.0-rc2","v5.2.0-rc1","v5.1.0","v5.1.0-rc2","v5.1.0-rc1","v5.0.0-rc2","v5.0.0-rc1","v4.10.0-rc2","v4.10.0-rc1","v4.9.0-rc1","v4.8.0-rc2","v4.8.0-rc1","v4.7.0-rc2","v4.7.0-rc1","v4.6.0-rc2","v4.6.0-rc1","v4.5.0","v4.5.0-rc2","v4.5.0-rc1","v4.4.0-rc2","v4.4.0-rc1","v4.1.0","v4.3.0-rc2","v4.3.0-rc1","v4.2.0-rc2","v4.2.0-rc1","CVE-2018-1064"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3667.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"63369119804262480602584117246342452608","length":747},"id":"CVE-2021-3667-57b6bb4d","signature_type":"Function","signature_version":"v1","source":"https://gitlab.com/libvirt/libvirt@447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87","target":{"file":"src/storage/storage_driver.c","function":"storagePoolLookupByTargetPath"}},{"deprecated":false,"digest":{"line_hashes":["195877491387619479579158237720163764491","90682379184772759765846818989144802475","317837978998188109099395814412819850670","336804048009231029245701955274722411095","94913288173034920064177808702328388873"],"threshold":0.9},"id":"CVE-2021-3667-cd1a45ce","signature_type":"Line","signature_version":"v1","source":"https://gitlab.com/libvirt/libvirt@447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87","target":{"file":"src/storage/storage_driver.c"}}],"vanir_signatures_modified":"2026-07-09T05:44:43Z"}}],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-06"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220331-0005/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1986094"},{"type":"FIX","url":"https://gitlab.com/libvirt/libvirt/-/commit/447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87"},{"type":"FIX","url":"https://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=447f69dec47e1b0bd15ecd7cd49a9fd3b050fb87"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}