Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:0711

Опубликовано: 03 мар. 2021
Источник: rocky
Оценка: Important

Описание

Important: virt:rhel and virt-devel:rhel security update

Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:Rocky Linux module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.

Security Fix(es):

  • QEMU: virtiofsd: potential privileged host device access from guest (CVE-2020-35517)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
hivexaarch6420.module+el8.4.0+534+4680a14ehivex-1.3.18-20.module+el8.4.0+534+4680a14e.aarch64.rpm
hivex-develaarch6420.module+el8.4.0+534+4680a14ehivex-devel-1.3.18-20.module+el8.4.0+534+4680a14e.aarch64.rpm
libguestfs-winsupportaarch641.module+el8.4.0+534+4680a14elibguestfs-winsupport-8.2-1.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsiaarch648.module+el8.7.0+1084+97b81f61libiscsi-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm
libiscsiaarch648.module+el8.4.0+534+4680a14elibiscsi-1.18.0-8.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsiaarch648.module+el8.6.0+847+b490afddlibiscsi-1.18.0-8.module+el8.6.0+847+b490afdd.aarch64.rpm
libiscsi-develaarch648.module+el8.7.0+1084+97b81f61libiscsi-devel-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm
libiscsi-develaarch648.module+el8.4.0+534+4680a14elibiscsi-devel-1.18.0-8.module+el8.4.0+534+4680a14e.aarch64.rpm
libiscsi-develaarch648.module+el8.6.0+847+b490afddlibiscsi-devel-1.18.0-8.module+el8.6.0+847+b490afdd.aarch64.rpm
libiscsi-utilsaarch648.module+el8.7.0+1084+97b81f61libiscsi-utils-1.18.0-8.module+el8.7.0+1084+97b81f61.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 5 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

CVSS3: 7.5
redhat
больше 5 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

CVSS3: 8.2
nvd
больше 5 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

CVSS3: 8.2
debian
больше 5 лет назад

A flaw was found in qemu. A host privilege escalation issue was found ...

CVSS3: 8.2
github
около 4 лет назад

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.