Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14339

Опубликовано: 17 июл. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in libvirt, where it leaked a file descriptor for /dev/mapper/control into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

This flaw was introduced in libvirt version 6.2.0. Red Hat Enterprise Linux 5, 6, 7, and 8 are not affected by this issue as they shipped an older version of the libvirt package which did not include the vulnerable code. This issue affects versions of the libvirt package as shipped with Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt package updates for Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue.

Меры по смягчению последствий

This issue is mitigated on Red Hat Enterprise Linux if SELinux is in enforcing mode, which prevents the /dev/mapper/control file descriptor from being accessible by a guest user/process.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.1/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtAffected
Red Hat Enterprise Linux 9libvirtNot affected
Advanced Virtualization for RHEL 8.2.1virtFixedRHSA-2020:358601.09.2020
Advanced Virtualization for RHEL 8.2.1virt-develFixedRHSA-2020:358601.09.2020
Red Hat Enterprise Linux 8virt-develFixedRHSA-2020:467604.11.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=1860069libvirt: leak of /dev/mapper/control into QEMU guests

EPSS

Процентиль: 21%
0.00066
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.8
nvd
больше 4 лет назад

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 8.8
debian
больше 4 лет назад

A flaw was found in libvirt, where it leaked a file descriptor for `/d ...

suse-cvrf
почти 5 лет назад

Security update for libvirt

suse-cvrf
почти 5 лет назад

Security update for libvirt

EPSS

Процентиль: 21%
0.00066
Низкий

8.8 High

CVSS3