A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1860069 Issue Tracking Patch Third Party Advisory
https://security.gentoo.org/glsa/202101-22 Third Party Advisory
https://security.gentoo.org/glsa/202210-06 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2020-12-03T00:00:00

Updated: 2022-10-16T00:00:00

Reserved: 2020-06-17T00:00:00


Link: CVE-2020-14339

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-03T17:15:12.207

Modified: 2022-11-07T18:56:54.207


Link: CVE-2020-14339

JSON object: View

cve-icon Redhat Information

No data.

CWE