GLSA Advocate

Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Jan 26, 2021 12:26 am Post subject: [ GLSA 202101-22 ] libvirt |
|
|
Gentoo Linux Security Advisory
Title: libvirt: Unintended access to /dev/mapper/control (GLSA 202101-22)
Severity: high
Exploitable: local
Date: 2021-01-26
Bug(s): #739948
ID: 202101-22
Synopsis
A vulnerability in libvirt may allow root privilege escalation.
Background
libvirt is a C toolkit for manipulating virtual machines.
Affected Packages
Package: app-emulation/libvirt
Vulnerable: < 6.7.0
Unaffected: >= 6.7.0
Architectures: All supported architectures
Description
A file descriptor for /dev/mapper/control was insufficiently protected.
Impact
A local attacker may be able to escalate to root privileges.
Workaround
There is no known workaround at this time.
Resolution
All libvirt users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/libvirt-6.7.0"
|
References
CVE-2020-14339 |
|