Описание
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Отчет
This flaw affects all versions of libvirt
as shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 8 Advanced Virtualization. A future update may address this issue.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | libvirt | Out of support scope | ||
Red Hat Enterprise Linux 7 | libvirt | Out of support scope | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libvirt | Affected | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.3/libvirt | Fix deferred | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libvirt | Affected | ||
Red Hat Enterprise Linux 9 | libvirt | Not affected | ||
Advanced Virtualization for RHEL 8.2.1 | virt | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.2.1 | virt-devel | Fixed | RHSA-2021:3704 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt | Fixed | RHSA-2021:3703 | 30.09.2021 |
Advanced Virtualization for RHEL 8.4.0.Z | virt-devel | Fixed | RHSA-2021:3703 | 30.09.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
3 Low
CVSS3
Связанные уязвимости
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
A flaw was found in libvirt while it generates SELinux MCS category pa ...
EPSS
3 Low
CVSS3