Medium severity4.3NVD Advisory· Published Mar 25, 2022· Updated Jun 17, 2026
CVE-2022-0897
CVE-2022-0897
Description
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the driver->nwfilters object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt's API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
41- osv-coords39 versionspkg:rpm/almalinux/libvirtpkg:rpm/almalinux/libvirt-clientpkg:rpm/almalinux/libvirt-daemonpkg:rpm/almalinux/libvirt-daemon-config-networkpkg:rpm/almalinux/libvirt-daemon-config-nwfilterpkg:rpm/almalinux/libvirt-daemon-driver-interfacepkg:rpm/almalinux/libvirt-daemon-driver-networkpkg:rpm/almalinux/libvirt-daemon-driver-nodedevpkg:rpm/almalinux/libvirt-daemon-driver-nwfilterpkg:rpm/almalinux/libvirt-daemon-driver-qemupkg:rpm/almalinux/libvirt-daemon-driver-secretpkg:rpm/almalinux/libvirt-daemon-driver-storagepkg:rpm/almalinux/libvirt-daemon-driver-storage-corepkg:rpm/almalinux/libvirt-daemon-driver-storage-diskpkg:rpm/almalinux/libvirt-daemon-driver-storage-iscsipkg:rpm/almalinux/libvirt-daemon-driver-storage-logicalpkg:rpm/almalinux/libvirt-daemon-driver-storage-mpathpkg:rpm/almalinux/libvirt-daemon-driver-storage-rbdpkg:rpm/almalinux/libvirt-daemon-driver-storage-scsipkg:rpm/almalinux/libvirt-daemon-kvmpkg:rpm/almalinux/libvirt-develpkg:rpm/almalinux/libvirt-docspkg:rpm/almalinux/libvirt-libspkg:rpm/almalinux/libvirt-lock-sanlockpkg:rpm/almalinux/libvirt-nsspkg:rpm/opensuse/libvirt&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/libvirt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/libvirt&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libvirt&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 8.5.0-7.el9_1+ 38 more
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 8.5.0-7.el9_1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 8.2.0-1.1
- (no CPE)range: < 6.0.0-150200.13.27.1
- (no CPE)range: < 6.0.0-150200.13.27.1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 7.1.0-150300.6.29.1
- (no CPE)range: < 5.1.0-13.31.1
- (no CPE)range: < 6.0.0-150200.13.27.1
- (no CPE)range: < 5.1.0-13.31.1
- (no CPE)range: < 6.0.0-150200.13.27.1
- (no CPE)range: < 5.1.0-13.31.1
Patches
Vulnerability mechanics
References
3- security.gentoo.org/glsa/202210-06nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- lists.debian.org/debian-lts-announce/2024/04/msg00000.htmlnvd
News mentions
0No linked articles in our index yet.