Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3631

Опубликовано: 13 апр. 2021
Источник: redhat
CVSS3: 3
EPSS Низкий

Описание

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

Отчет

This flaw affects all versions of libvirt as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 8 Advanced Virtualization. A future update may address this issue.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtAffected
Red Hat Enterprise Linux 9libvirtNot affected
Advanced Virtualization for RHEL 8.2.1virtFixedRHSA-2021:370430.09.2021
Advanced Virtualization for RHEL 8.2.1virt-develFixedRHSA-2021:370430.09.2021
Advanced Virtualization for RHEL 8.4.0.ZvirtFixedRHSA-2021:370330.09.2021
Advanced Virtualization for RHEL 8.4.0.Zvirt-develFixedRHSA-2021:370330.09.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1977726libvirt: Insecure sVirt label generation

EPSS

Процентиль: 11%
0.00039
Низкий

3 Low

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
nvd
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 6.3
debian
больше 3 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pa ...

suse-cvrf
почти 4 года назад

Security update for libvirt

EPSS

Процентиль: 11%
0.00039
Низкий

3 Low

CVSS3