Описание
A flaw was found in libvirt, where it leaked a file descriptor for /dev/mapper/control
into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Отчет
This flaw was introduced in libvirt
version 6.2.0. Red Hat Enterprise Linux 5, 6, 7, and 8 are not affected by this issue as they shipped an older version of the libvirt
package which did not include the vulnerable code.
This issue affects versions of the libvirt
package as shipped with Red Hat Enterprise Linux Advanced Virtualization 8. Future libvirt
package updates for Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue.
Меры по смягчению последствий
This issue is mitigated on Red Hat Enterprise Linux if SELinux is in enforcing mode, which prevents the /dev/mapper/control
file descriptor from being accessible by a guest user/process.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | libvirt | Not affected | ||
Red Hat Enterprise Linux 6 | libvirt | Not affected | ||
Red Hat Enterprise Linux 7 | libvirt | Not affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.1/libvirt | Not affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libvirt | Affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.3/libvirt | Affected | ||
Red Hat Enterprise Linux 9 | libvirt | Not affected | ||
Advanced Virtualization for RHEL 8.2.1 | virt | Fixed | RHSA-2020:3586 | 01.09.2020 |
Advanced Virtualization for RHEL 8.2.1 | virt-devel | Fixed | RHSA-2020:3586 | 01.09.2020 |
Red Hat Enterprise Linux 8 | virt-devel | Fixed | RHSA-2020:4676 | 04.11.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A flaw was found in libvirt, where it leaked a file descriptor for `/d ...
EPSS
8.8 High
CVSS3