libvirt: unsafe usage of paths under /proc/$PID/root
Published Apr 15, 2014
5.8
MEDIUMCVSS 2.0
EPSS 0.58%
Description
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
Affected products
No data.
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.5.1
- 1.0.5.2
- 1.0.5.3
- 1.0.5.4
- 1.0.5.5
- 1.0.5.6
- 1.0.6
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.2.0
- 1.2.1
- 20
No data.
Red Hat Enterprise Linux 5
libvirt
Not affected
Red Hat Enterprise Linux 6
libvirt
Not affected
Red Hat Enterprise Linux 7
libvirt
Will not fix
Red Hat Storage 2
libvirt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libvirt | Will not fix | n/a |
| Red Hat Storage 2 | libvirt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=5fc590ad9f4 x_refsource_CONFIRM
- http://libvirt.org/news.html x_refsource_CONFIRM
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129199.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00004.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/56187 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/56215 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/60895 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-04.xml vendor-advisoryx_refsource_GENTOO
- http://security.libvirt.org/2013/0018.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/65743 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-6456 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732394 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=1045643 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1048627 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-6456
- https://www.cve.org/CVERecord?id=CVE-2013-6456
Change history (0)
No recorded changes yet.