A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3778-1 | libvirt security update |
Ubuntu USN |
USN-5399-1 | libvirt vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-11-19T19:33:55.041Z
Reserved: 2021-06-30T00:00:00
Link: CVE-2021-3631
Updated: 2024-08-03T17:01:08.363Z
Status : Modified
Published: 2022-03-02T23:15:08.677
Modified: 2024-11-21T06:22:01.480
Link: CVE-2021-3631
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN