[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252271

 
 

909

 
 

196835

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)

ID: oval:org.secpod.oval:def:1801750Date: (C)2020-12-23   (M)2022-11-14
Class: PATCHFamily: unix




It was discovered that libvirt is accidentally leaking a file descriptor for /dev/mapper/control into the QEMU process. This file descriptor allows for privileged operations to be made against device mapper on the host. Thus a malicious QEMU has the potential to do serious damage to the host OS.

Platform:
Alpine Linux 3.12
Product:
libvirt
Reference:
11856
CVE-2020-14339
CVE    1
CVE-2020-14339
CPE    1
cpe:/a:redhat:libvirt

© SecPod Technologies