DEBIAN-CVE-2023-3750

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2023-3750
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-3750.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2023-3750
Upstream
Published
2023-07-24T16:15:13Z
Modified
2025-09-19T07:33:22.481447Z
Summary
[none]
Details

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.

References

Affected packages

Debian:12 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0-4+deb12u1

Affected versions

9.*

9.0.0-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.6.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.6.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}