CVE-2020-14339

medium
Published 2020-11-03 Β· Modified 2020-11-04
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2020:4676: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description libvirt: leak of /dev/mapper/control into QEMU guests Red Hat statement This flaw was introduced in `libvirt` version 6.2.0. Red Hat Enterprise Linux 5, 6, 7, and 8 are not affected by this issue as they shipped an older version of the `libvirt` package which did not include the vulnerable code. This issue affects versions of the `libvirt` package as shipped with Red Hat Enterprise…

Description

libvirt: leak of /dev/mapper/control into QEMU guests

Red Hat statement

This flaw was introduced in `libvirt` version 6.2.0. Red Hat Enterprise Linux 5, 6, 7, and 8 are not affected by this issue as they shipped an older version of the `libvirt` package which did not include the vulnerable code. This issue affects versions of the `libvirt` package as shipped with Red Hat Enterprise Linux Advanced Virtualization 8. Future `libvirt` package updates for Red Hat Enterprise Linux Advanced Virtualization 8 may address this issue.

CVSS v3: 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Advanced Virtualization for RHEL 8.2.1virt:8.2-8020120200820190722.863bb0dbRHSA-2020:35862020-09-01T00:00:00Z
Advanced Virtualization for RHEL 8.2.1virt-devel:8.2-8020120200820190722.863bb0dbRHSA-2020:35862020-09-01T00:00:00Z
Red Hat Enterprise Linux 8virt-devel:rhel-8030020200909014558.30b713e6RHSA-2020:46762020-11-04T00:00:00Z
Red Hat Enterprise Linux 8virt:rhel-8030020200909014558.30b713e6RHSA-2020:46762020-11-04T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Enterprise Linux 7libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.1/libvirtNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/libvirtAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/libvirtAffected
Red Hat Enterprise Linux 9libvirtNot affected

Apply commands

bash fix
Apply RHSA-2020:3586 for Advanced Virtualization for RHEL 8.2.1
yum update -y virt:8
# or:
dnf upgrade -y virt:8

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 5Not affected
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 8 Advanced VirtualizationNot affected
redhatRed Hat Enterprise Linux 8 Advanced VirtualizationAffected
redhatRed Hat Enterprise Linux 8 Advanced VirtualizationAffected
redhatRed Hat Enterprise Linux 9Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 6.5.0-2
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 6.6.0-1
sid Fixed 6.6.0-1
forky Fixed 6.6.0-1
bullseye Fixed 6.6.0-1
bookworm Fixed 6.6.0-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.