A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2033697 | issue tracking third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=2039248 | issue tracking third party advisory |
https://gerrit.ovirt.org/c/vdsm/+/118025 | patch vendor advisory |
https://gerrit.ovirt.org/gitweb?p=vdsm.git%3Ba=commit%3Bh=53b0036fc72d3b8877d4e7f047d705e5a4c722e8 | |
https://access.redhat.com/security/cve/CVE-2022-0207 | third party advisory |