Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2020-14339 (GCVE-0-2020-14339)
Vulnerability from cvelistv5 – Published: 2020-12-03 00:00 – Updated: 2024-08-04 12:39| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1860069 | |
| https://security.gentoo.org/glsa/202101-22 | vendor-advisory |
| https://security.gentoo.org/glsa/202210-06 | vendor-advisory |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-04T12:39:36.530Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"name": "GLSA-202101-22",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"name": "GLSA-202210-06",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202210-06"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "libvirt",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "libvirt 6.6.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability."
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-772",
"description": "CWE-772",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2022-10-16T00:00:00.000Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"name": "GLSA-202101-22",
"tags": [
"vendor-advisory"
],
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"name": "GLSA-202210-06",
"tags": [
"vendor-advisory"
],
"url": "https://security.gentoo.org/glsa/202210-06"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2020-14339",
"datePublished": "2020-12-03T00:00:00.000Z",
"dateReserved": "2020-06-17T00:00:00.000Z",
"dateUpdated": "2024-08-04T12:39:36.530Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1",
"vulnerability-lookup:meta": {
"epss": {
"cve": "CVE-2020-14339",
"date": "2026-10-03",
"epss": "0.00421",
"percentile": "0.34188"
}
}
}
ALSA-2020:4676
Vulnerability from osv_almalinux – Published: 2020-11-03 12:26 – Updated: 2021-12-23 15:15 – Source websiteKernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.
The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296)
Security Fix(es):
-
libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)
-
QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890)
-
libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485)
-
QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983)
-
libvirt: Potential denial of service via active pool without target path (CVE-2020-10703)
-
libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
{
"affected": [
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "hivex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "hivex-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libguestfs-winsupport"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.2-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libguestfs-winsupport"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "8.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-utils"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-utils"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libiscsi-utils"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.18.0-8.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libnbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libnbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libnbd-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libnbd-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-admin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-bash-completion"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-client"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-config-network"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-config-nwfilter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-interface"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-network"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-nodedev"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-nwfilter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-secret"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-disk"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-iscsi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-iscsi-direct"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-logical"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-mpath"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-rbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-daemon-driver-storage-scsi"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-dbus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.0-2.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-dbus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.0-2.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-dbus"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.0-2.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-docs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "libvirt-nss"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-28.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdfuse"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdfuse"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-bash-completion"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-basic-filters"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-basic-plugins"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-curl-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-example-plugins"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-gzip-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-linuxdisk-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-python-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-ssh-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-vddk-plugin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "nbdkit-xz-filter"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.2-4.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "netcf-libs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.8-12.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-hivex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-hivex-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-libguestfs"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:1.40.2-25.module_el8.3.0+2048+e7a0a3ea.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-libguestfs-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:1.40.2-25.module_el8.3.0+2048+e7a0a3ea.alma"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-libnbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ocaml-libnbd-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "perl-Sys-Virt"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "perl-Sys-Virt"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "perl-hivex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-hivex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-libnbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-libnbd"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.2-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-libvirt"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-1.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "python3-libvirt"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.0.0-1.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "ruby-hivex"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.3.18-20.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "seabios"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13.0-2.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "seabios-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13.0-2.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "seavgabios-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.13.0-2.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "sgabios"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:0.20170427git-3.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "sgabios"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:0.20170427git-3.module_el8.3.0+2048+e7a0a3ea"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "sgabios-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:0.20170427git-3.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "sgabios-bin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1:0.20170427git-3.module_el8.6.0+2880+7d9e3703"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "supermin"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.1.19-10.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"package": {
"ecosystem": "AlmaLinux:8",
"name": "supermin-devel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.1.19-10.module_el8.5.0+2608+72063365"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"details": "Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.\n\nThe following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296)\n\nSecurity Fix(es):\n\n* libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)\n\n* QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890)\n\n* libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485)\n\n* QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983)\n\n* libvirt: Potential denial of service via active pool without target path (CVE-2020-10703)\n\n* libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.",
"id": "ALSA-2020:4676",
"modified": "2021-12-23T15:15:25Z",
"published": "2020-11-03T12:26:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://errata.almalinux.org/8/ALSA-2020-4676.html"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2019-15890"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2019-20485"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2020-10703"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2020-14301"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2020-14339"
},
{
"type": "REPORT",
"url": "https://vulners.com/cve/CVE-2020-1983"
}
],
"related": [
"CVE-2020-14339",
"CVE-2019-15890",
"CVE-2019-20485",
"CVE-2020-1983",
"CVE-2020-10703",
"CVE-2020-14301"
],
"summary": "Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update"
}
BELL-CVE-2020-14339 (CVE-2020-14339)
Vulnerability from osv_bellsoft – Published: 2023-08-31 12:16 – Updated: 2023-08-31 12:16 – Source website| URL | Type | |
|---|---|---|
{
"id": "BELL-CVE-2020-14339",
"modified": "2023-08-31T12:16:12.887858Z",
"published": "2023-08-31T12:16:12.887854Z",
"references": [
{
"type": "ADVISORY",
"url": "https://docs.bell-sw.com/security/cves/CVE-2020-14339"
}
],
"schema_version": "1.7.4",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "CVE-2020-14339 does not affect BellSoft software",
"upstream": [
"CVE-2020-14339"
],
"withdrawn": "2023-08-31T12:16:12.887858Z"
}
厂商已发布了漏洞修复程序,请及时关注更新: https://libvirt.org/git/?p=libvirt.git;a=commit;h=22494556542c676d1b9e7f1c1f2ea13ac17e1e3e
| Name | Red Hat libvirt |
|---|
{
"cves": {
"cve": {
"cveNumber": "CVE-2020-14339",
"cveUrl": "https://nvd.nist.gov/vuln/detail/CVE-2020-14339"
}
},
"description": "Red Hat libvirt\u662f\u7f8e\u56fd\u7ea2\u5e3d\uff08Red Hat\uff09\u516c\u53f8\u7684\u4e00\u4e2a\u7528\u4e8e\u5b9e\u73b0Linux\u865a\u62df\u5316\u529f\u80fd\u7684Linux API\uff0c\u5b83\u652f\u6301\u5404\u79cdHypervisor\uff0c\u5305\u62ecXen\u548cKVM\uff0c\u4ee5\u53caQEMU\u548c\u7528\u4e8e\u5176\u4ed6\u64cd\u4f5c\u7cfb\u7edf\u7684\u4e00\u4e9b\u865a\u62df\u4ea7\u54c1\u3002\n\nRed Hat libvirt\u4e2d\u5b58\u5728\u6743\u9650\u63d0\u5347\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u7ed5\u8fc7\u9650\u5236\uff0c\u63d0\u5347\u6743\u9650\u3002",
"formalWay": "\u5382\u5546\u5df2\u53d1\u5e03\u4e86\u6f0f\u6d1e\u4fee\u590d\u7a0b\u5e8f\uff0c\u8bf7\u53ca\u65f6\u5173\u6ce8\u66f4\u65b0\uff1a\r\nhttps://libvirt.org/git/?p=libvirt.git;a=commit;h=22494556542c676d1b9e7f1c1f2ea13ac17e1e3e",
"isEvent": "\u901a\u7528\u8f6f\u786c\u4ef6\u6f0f\u6d1e",
"number": "CNVD-2020-47042",
"openTime": "2020-08-20",
"patchDescription": "Red Hat libvirt\u662f\u7f8e\u56fd\u7ea2\u5e3d\uff08Red Hat\uff09\u516c\u53f8\u7684\u4e00\u4e2a\u7528\u4e8e\u5b9e\u73b0Linux\u865a\u62df\u5316\u529f\u80fd\u7684Linux API\uff0c\u5b83\u652f\u6301\u5404\u79cdHypervisor\uff0c\u5305\u62ecXen\u548cKVM\uff0c\u4ee5\u53caQEMU\u548c\u7528\u4e8e\u5176\u4ed6\u64cd\u4f5c\u7cfb\u7edf\u7684\u4e00\u4e9b\u865a\u62df\u4ea7\u54c1\u3002\r\n\r\nRed Hat libvirt\u4e2d\u5b58\u5728\u6743\u9650\u63d0\u5347\u6f0f\u6d1e\uff0c\u653b\u51fb\u8005\u53ef\u5229\u7528\u8be5\u6f0f\u6d1e\u7ed5\u8fc7\u9650\u5236\uff0c\u63d0\u5347\u6743\u9650\u3002\u76ee\u524d\uff0c\u4f9b\u5e94\u5546\u53d1\u5e03\u4e86\u5b89\u5168\u516c\u544a\u53ca\u76f8\u5173\u8865\u4e01\u4fe1\u606f\uff0c\u4fee\u590d\u4e86\u6b64\u6f0f\u6d1e\u3002",
"patchName": "Red Hat libvirt\u6743\u9650\u63d0\u5347\u6f0f\u6d1e\u7684\u8865\u4e01",
"products": {
"product": "Red Hat libvirt"
},
"referenceLink": "https://vigilance.fr/vulnerability/libvirt-privilege-escalation-via-dev-mapper-control-33077",
"serverity": "\u4e2d",
"submitTime": "2020-08-17",
"title": "Red Hat libvirt\u6743\u9650\u63d0\u5347\u6f0f\u6d1e\uff08CNVD-2020-47042\uff09"
}
FKIE_CVE-2020-14339
Vulnerability from fkie_nvd - Published: 2020-12-03 17:15 - Updated: 2026-06-17 02:54| URL | Tags | ||
|---|---|---|---|
| secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1860069 | Issue Tracking, Patch, Third Party Advisory | |
| secalert@redhat.com | https://security.gentoo.org/glsa/202101-22 | Third Party Advisory | |
| secalert@redhat.com | https://security.gentoo.org/glsa/202210-06 | Third Party Advisory | |
| af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1860069 | Issue Tracking, Patch, Third Party Advisory | |
| af854a3a-2127-422b-91ae-364da2661108 | https://security.gentoo.org/glsa/202101-22 | Third Party Advisory | |
| af854a3a-2127-422b-91ae-364da2661108 | https://security.gentoo.org/glsa/202210-06 | Third Party Advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| redhat | libvirt | * | |
| redhat | enterprise_linux | 8.0 |
{
"affected": [
{
"affectedData": [
{
"product": "libvirt",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "libvirt 6.6.0"
}
]
}
],
"source": "secalert@redhat.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C37FC2C5-3E40-4531-AE8C-97EB33B624A2",
"versionEndExcluding": "6.7.0",
"versionStartIncluding": "6.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*",
"matchCriteriaId": "3AA08768-75AF-4791-B229-AE938C780959",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability."
},
{
"lang": "es",
"value": "Se encontr\u00f3 un fallo en libvirt, donde filtr\u00f3 un descriptor de archivo para \"/dev/mapper/control\" en el proceso QEMU.\u0026#xa0;Este descriptor de archivo permite que operaciones privilegiadas sean realizadas contra el mapeador de dispositivos en el host.\u0026#xa0;este fallo permite a un usuario o proceso invitado malicioso llevar a cabo operaciones fuera de sus permisos est\u00e1ndar, lo que podr\u00eda causar da\u00f1os graves al sistema operativo del host.\u0026#xa0;La mayor amenaza de esta vulnerabilidad es la confidencialidad, la integridad y la disponibilidad del sistema"
}
],
"id": "CVE-2020-14339",
"lastModified": "2026-06-17T02:54:33.993",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "LOCAL",
"authentication": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2,
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"version": "2.0"
},
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "nvd@nist.gov",
"type": "Primary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.0,
"impactScore": 6.0,
"source": "nvd@nist.gov",
"type": "Primary"
}
]
},
"published": "2020-12-03T17:15:12.207",
"references": [
{
"source": "secalert@redhat.com",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202210-06"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202210-06"
}
],
"sourceIdentifier": "secalert@redhat.com",
"vulnStatus": "Modified",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-772"
}
],
"source": "secalert@redhat.com",
"type": "Secondary"
},
{
"description": [
{
"lang": "en",
"value": "CWE-772"
}
],
"source": "nvd@nist.gov",
"type": "Secondary"
}
]
}
GHSA-C772-G5J9-W9W8
Vulnerability from github – Published: 2022-05-24 17:35 – Updated: 2022-10-16 19:00A flaw was found in libvirt, where it leaked a file descriptor for /dev/mapper/control into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
{
"affected": [],
"aliases": [
"CVE-2020-14339"
],
"database_specific": {
"cwe_ids": [
"CWE-772"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2020-12-03T17:15:00Z",
"severity": "HIGH"
},
"details": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
"id": "GHSA-c772-g5j9-w9w8",
"modified": "2022-10-16T19:00:30Z",
"published": "2022-05-24T17:35:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14339"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202210-06"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GSD-2020-14339
Vulnerability from gsd - Updated: 2023-12-13 01:22{
"GSD": {
"alias": "CVE-2020-14339",
"description": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
"id": "GSD-2020-14339",
"references": [
"https://www.suse.com/security/cve/CVE-2020-14339.html",
"https://access.redhat.com/errata/RHSA-2020:4676",
"https://access.redhat.com/errata/RHSA-2020:3586",
"https://security.archlinux.org/CVE-2020-14339",
"https://linux.oracle.com/cve/CVE-2020-14339.html"
]
},
"gsd": {
"metadata": {
"exploitCode": "unknown",
"remediation": "unknown",
"reportConfidence": "confirmed",
"type": "vulnerability"
},
"osvSchema": {
"aliases": [
"CVE-2020-14339"
],
"details": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
"id": "GSD-2020-14339",
"modified": "2023-12-13T01:22:00.350170Z",
"schema_version": "1.4.0"
}
},
"namespaces": {
"cve.org": {
"CVE_data_meta": {
"ASSIGNER": "secalert@redhat.com",
"ID": "CVE-2020-14339",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "libvirt",
"version": {
"version_data": [
{
"version_value": "libvirt 6.6.0"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-772"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069",
"refsource": "MISC",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"name": "GLSA-202101-22",
"refsource": "GENTOO",
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"name": "GLSA-202210-06",
"refsource": "GENTOO",
"url": "https://security.gentoo.org/glsa/202210-06"
}
]
}
},
"nvd.nist.gov": {
"configurations": {
"CVE_data_version": "4.0",
"nodes": [
{
"children": [],
"cpe_match": [
{
"cpe23Uri": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*",
"cpe_name": [],
"vulnerable": true
},
{
"cpe23Uri": "cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*",
"cpe_name": [],
"versionEndExcluding": "6.7.0",
"versionStartIncluding": "6.2.0",
"vulnerable": true
}
],
"operator": "OR"
}
]
},
"cve": {
"CVE_data_meta": {
"ASSIGNER": "secalert@redhat.com",
"ID": "CVE-2020-14339"
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "en",
"value": "A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "en",
"value": "CWE-772"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069",
"refsource": "MISC",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1860069"
},
{
"name": "GLSA-202101-22",
"refsource": "GENTOO",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202101-22"
},
{
"name": "GLSA-202210-06",
"refsource": "GENTOO",
"tags": [
"Third Party Advisory"
],
"url": "https://security.gentoo.org/glsa/202210-06"
}
]
}
},
"impact": {
"baseMetricV2": {
"acInsufInfo": false,
"cvssV2": {
"accessComplexity": "LOW",
"accessVector": "LOCAL",
"authentication": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 7.2,
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"version": "2.0"
},
"exploitabilityScore": 3.9,
"impactScore": 10.0,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"severity": "HIGH",
"userInteractionRequired": false
},
"baseMetricV3": {
"cvssV3": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.0,
"impactScore": 6.0
}
},
"lastModifiedDate": "2022-11-07T18:56Z",
"publishedDate": "2020-12-03T17:15Z"
}
}
}
OESA-2021-1010 (CVE-2020-14339)
Vulnerability from osv_openeuler – Published: 2021-02-04 11:04 – Updated: 2026-08-06 11:04 – Source websiteLibvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.\r\n\r\n
Security Fix(es):\r\n\r\n
A flaw was found in libvirt, where it leaked a file descriptor for /dev/mapper/control into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-14339)\r\n\r\n
| URL | Type | |
|---|---|---|
{
"affected": [
{
"ecosystem_specific": {
"aarch64": [
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-libs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-admin-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.aarch64.rpm",
"libvirt-nss-6.2.0-10.oe1.aarch64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-lock-sanlock-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.aarch64.rpm",
"libvirt-docs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.aarch64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-6.2.0-10.oe1.aarch64.rpm",
"libvirt-client-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-6.2.0-10.oe1.aarch64.rpm",
"libvirt-devel-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-libs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-admin-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.aarch64.rpm",
"libvirt-nss-6.2.0-10.oe1.aarch64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-lock-sanlock-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.aarch64.rpm",
"libvirt-docs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.aarch64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-6.2.0-10.oe1.aarch64.rpm",
"libvirt-client-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-6.2.0-10.oe1.aarch64.rpm",
"libvirt-devel-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.aarch64.rpm"
],
"src": [
"libvirt-6.2.0-10.oe1.src.rpm",
"libvirt-6.2.0-10.oe1.src.rpm"
],
"x86_64": [
"libvirt-lock-sanlock-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-nss-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.x86_64.rpm",
"libvirt-libs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-devel-6.2.0-10.oe1.x86_64.rpm",
"libvirt-docs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.x86_64.rpm",
"libvirt-admin-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.x86_64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.x86_64.rpm",
"libvirt-client-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-6.2.0-10.oe1.x86_64.rpm",
"libvirt-lock-sanlock-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-nss-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.x86_64.rpm",
"libvirt-libs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-devel-6.2.0-10.oe1.x86_64.rpm",
"libvirt-docs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.x86_64.rpm",
"libvirt-admin-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.x86_64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.x86_64.rpm",
"libvirt-client-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-6.2.0-10.oe1.x86_64.rpm"
]
},
"package": {
"ecosystem": "openEuler:20.03-LTS",
"name": "libvirt",
"purl": "pkg:rpm/openEuler/libvirt\u0026distro=openEuler-20.03-LTS"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.2.0-10.oe1"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"ecosystem_specific": {
"aarch64": [
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-libs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-admin-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.aarch64.rpm",
"libvirt-nss-6.2.0-10.oe1.aarch64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.aarch64.rpm",
"libvirt-lock-sanlock-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.aarch64.rpm",
"libvirt-docs-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.aarch64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.aarch64.rpm",
"libvirt-6.2.0-10.oe1.aarch64.rpm",
"libvirt-client-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.aarch64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-6.2.0-10.oe1.aarch64.rpm",
"libvirt-devel-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.aarch64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.aarch64.rpm"
],
"src": [
"libvirt-6.2.0-10.oe1.src.rpm"
],
"x86_64": [
"libvirt-lock-sanlock-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-nss-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-logical-6.2.0-10.oe1.x86_64.rpm",
"libvirt-libs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-devel-6.2.0-10.oe1.x86_64.rpm",
"libvirt-docs-6.2.0-10.oe1.x86_64.rpm",
"libvirt-wireshark-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-iscsi-direct-6.2.0-10.oe1.x86_64.rpm",
"libvirt-admin-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-gluster-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-scsi-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-core-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-interface-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-kvm-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debugsource-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-rbd-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-disk-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-nodedev-6.2.0-10.oe1.x86_64.rpm",
"libvirt-bash-completion-6.2.0-10.oe1.x86_64.rpm",
"libvirt-client-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-network-6.2.0-10.oe1.x86_64.rpm",
"libvirt-debuginfo-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-storage-mpath-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-qemu-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-driver-secret-6.2.0-10.oe1.x86_64.rpm",
"libvirt-daemon-config-nwfilter-6.2.0-10.oe1.x86_64.rpm",
"libvirt-6.2.0-10.oe1.x86_64.rpm"
]
},
"package": {
"ecosystem": "openEuler:20.03-LTS-SP1",
"name": "libvirt",
"purl": "pkg:rpm/openEuler/libvirt\u0026distro=openEuler-20.03-LTS-SP1"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "6.2.0-10.oe1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"severity": "High"
},
"details": "Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.\\r\\n\\r\\n\r\nSecurity Fix(es):\\r\\n\\r\\n\r\nA flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-14339)\\r\\n\\r\\n",
"id": "OESA-2021-1010",
"modified": "2026-08-06T11:04:14Z",
"published": "2021-02-04T11:04:14Z",
"references": [
{
"type": "ADVISORY",
"url": "https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1010"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14339"
}
],
"schema_version": "1.7.2",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "libvirt security update",
"upstream": [
"CVE-2020-14339"
]
}
OPENSUSE-SU-2020:1455-1
Vulnerability from csaf_opensuse - Published: 2020-09-19 12:20 - Updated: 2026-09-20 19:13OPENSUSE-SU-2024:11008-1
Vulnerability from csaf_opensuse - Published: 2024-06-15 00:00 - Updated: 2026-09-20 20:09RHSA-2020:3586
Vulnerability from csaf_redhat - Published: 2020-09-01 09:42 - Updated: 2026-06-28 08:53A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.