CVE-2020-14339
Summary
| CVE | CVE-2020-14339 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-03 17:15:00 UTC |
| Updated | 2022-11-07 18:56:00 UTC |
| Description | A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| libvirt: Multiple Vulnerabilities (GLSA 202210-06) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| libvirt: Unintended access to /dev/mapper/control (GLSA 202101-22) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| 1860069 – (CVE-2020-14339) CVE-2020-14339 libvirt: leak of /dev/mapper/control into QEMU guests |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159669 Oracle Enterprise Linux Security Update for virt:ol and virt-devel:rhel (ELSA-2020-4676)
- 377413 Alibaba Cloud Linux Security Update for virt:rhel and virt-devel:rhel (ALINUX3-SA-2022:0119)
- 500326 Alpine Linux Security Update for libvirt
- 710643 Gentoo Linux libvirt Multiple Vulnerabilities (GLSA 202210-06)
- 940165 AlmaLinux Security Update for virt:rhel and virt-devel:rhel (ALSA-2020:4676)
- 960273 Rocky Linux Security Update for virt:rhel and virt-devel:rhel (RLSA-2020:4676)