CVE-2010-2238
published 2010-08-19CVE-2010-2238: Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might…
PriorityP419medium4.4CVSS 2.0
AVLACMAuSCCINAN
EPSS
0.32%
23.7th percentile
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.9.1-2 (bookworm) | libvirt 0.9.1-2 (bookworm) |
| debian | libvirt | < libvirt 0.8.3-1 (bookworm) | libvirt 0.8.3-1 (bookworm) |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 0.8.3-1 | 0.8.3-1 |
| redhat | libvirt | >= 0 < 0.9.1-2 | 0.9.1-2 |
| redhat | libvirt | >= 0 < 0.8.3-1 | 0.8.3-1 |
| redhat | libvirt | >= 0 < 0.9.1-2 | 0.9.1-2 |
| redhat | libvirt | >= 0 < 0.8.3-1 | 0.8.3-1 |
| redhat | libvirt | >= 0 < 0.9.1-2 | 0.9.1-2 |
| redhat | libvirt | >= 0 < 0.8.3-1 | 0.8.3-1 |
| redhat | libvirt | >= 0 < 0.9.1-2 | 0.9.1-2 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:S/C:C/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2011-06-16·CVSS 4.4
CVE-2011-1486 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Libvirt could be made to crash or read arbitrary files on the host.
It was discovered that libvirt did not use thread-safe error reporting. A
remote attacker could exploit this to cause a denial of service via
application crash. (CVE-2011-1486)
Eric Blake discovered that libvirt had an off-by-one error which could
be used to reopen disk probing and bypass the fix for CVE-2010-2238. A
privileged attacker in the guest could exploit this to read arbitrary files
on the host. This issue only affected Ubuntu 11.04. By default, guests are
confined by an AppArmor profile which provided partial protection against
this flaw. (CVE-2011-2178)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvirt: regression introduced in disk probe logic
vendor_redhat·2011-05-31·CVSS 4.4
CVE-2011-2178 [MEDIUM] libvirt: regression introduced in disk probe logic
libvirt: regression introduced in disk probe logic
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
Statement: Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5 and 6 as we did not backport upstream commit d6623003.
Package: libvirt (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2011-2178: libvirt - The virSecurityManagerGetPrivateData function in security/security_manager.c in ...
vendor_debian·2011·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178: libvirt - The virSecurityManagerGetPrivateData function in security/security_manager.c in ...
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
Scope: local
bookworm: resolved (fixed in 0.9.1-2)
bullseye: resolved (fixed in 0.9.1-2)
forky: resolved (fixed in 0.9.1-2)
sid: resolved (fixed in 0.9.1-2)
trixie: resolved (fixed in 0.9.1-2)
Ubuntu
libvirt regression
vendor_ubuntu·2010-11-08·CVSS 4.4
CVE-2010-2238 [MEDIUM] libvirt regression
Title: libvirt regression
Summary: This update restores 'host_device' support for domain XML on Ubuntu 10.04
LTS.
USN-1008-1 fixed vulnerabilities in libvirt. The upstream fixes for
CVE-2010-2238 changed the behavior of libvirt such that the domain
XML could not specify 'host_device' as the qemu sub-type. While libvirt
0.8.3 and later will longer support specifying this sub-type, this
update restores the old behavior on Ubuntu 10.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
App
Ubuntu
libvirt update
vendor_ubuntu·2010-10-23·CVSS 4.4
[MEDIUM] libvirt update
Title: libvirt update
Summary: This update reenables recent bug fixes.
USN-1008-1 fixed vulnerabilities in libvirt. The update for Ubuntu 10.04
LTS reverted a recent bug fix update. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
AppArmor profile which provided partial protection against this flaw.
(CVE-2010-2237, CVE-2010-2238)
It was discovered that libvirt would create new VMs without setting a
backing store format. A privileged attacker in the guest cou
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2010-10-21·CVSS 4.4
CVE-2010-2237 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Guest VMs could be made to circumvent security protections to access
resources on the host.
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
AppArmor profile which provided partial protection against this flaw.
(CVE-2010-2237, CVE-2010-2238)
It was discovered that libvirt would create new VMs without setting a
backing store format. A privileged attacker in the guest could exploit this
to read arbitrary files on the host. This issue did not affect Ubuntu 8.04
LTS. In Ubuntu 9.10 and later guests are confined by an
Ubuntu
Virtinst update
vendor_ubuntu·2010-10-21·CVSS 4.4
[MEDIUM] Virtinst update
Title: Virtinst update
Summary: Updated virtinst for use with the new libvirt.
Libvirt in Ubuntu 10.04 LTS now no longer probes qemu disks for the image
format and defaults to 'raw' when the format is not specified in the XML.
This change in behavior breaks virt-install --import because virtinst in
Ubuntu 10.04 LTS did not allow for specifying a disk format and does not
specify a format in the XML. This update adds the 'format=' option when
specifying a disk. For example, to import an existing VM which uses a qcow2
disk format, use somthing like the following:
virt-install --connect=qemu:///session --name test-import --ram=256 \
--disk path=,format=qcow2 --import
For more information, see man 1 virt-install.
Original advisory details:
It was discovered that libvirt would probe disk b
Red Hat
libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
vendor_redhat·2010-07-12·CVSS 4.4
CVE-2010-2238 [MEDIUM] libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
Statement: Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5.
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2238: libvirt - Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing ...
vendor_debian·2010·CVSS 4.4
CVE-2010-2238 [MEDIUM] CVE-2010-2238: libvirt - Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing ...
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.8.3-1)
bullseye: resolved (fixed in 0.8.3-1)
forky: resolved (fixed in 0.8.3-1)
sid: resolved (fixed in 0.8.3-1)
trixie: resolved (fixed in 0.8.3-1)
GHSA
GHSA-5383-rqrv-fg4g: The virSecurityManagerGetPrivateData function in security/security_manager
ghsa_unreviewed·2022-05-17·CVSS 4.4
CVE-2011-2178 [MEDIUM] GHSA-5383-rqrv-fg4g: The virSecurityManagerGetPrivateData function in security/security_manager
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
GHSA
GHSA-xvqx-w57v-q544: Red Hat libvirt, possibly 0
ghsa_unreviewed·2022-05-17
CVE-2010-2238 [MEDIUM] GHSA-xvqx-w57v-q544: Red Hat libvirt, possibly 0
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
OSV
CVE-2011-2178: The virSecurityManagerGetPrivateData function in security/security_manager
osv·2011-08-10·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178: The virSecurityManagerGetPrivateData function in security/security_manager
The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
OSV
CVE-2010-2238: Red Hat libvirt, possibly 0
osv·2010-08-19·CVSS 4.4
CVE-2010-2238 [MEDIUM] CVE-2010-2238: Red Hat libvirt, possibly 0
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
No detection rules found.
Bugzilla
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-rawhide]
bugzilla·2011-06-01·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-rawhide]
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-rawhide]
fedora-rawhide tracking bug for libvirt: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Probably easiest to solve rawhide by building 0.9.2 rather than trying to backport:
commit b598ac555c8fe67ffc39ac8ef25fe7e6b28ae3f2
Author: Eric Blake
Date: Thu May 26 08:18:46 2011 -0600
security: plug regression introduced in disk probe logic
wrong sizeof operand meant that security manager private data
was overlaying the allowDiskFormatProbing member of struct
_virSecurityManager. This reopens disk probing, which was
supposed to be prevente
Bugzilla
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
bugzilla·2011-06-01·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
CVE-2011-2178 libvirt: regression introduced in disk probe logic [fedora-15]
fedora-15 tracking bug for libvirt: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This upstream commit needs to be backported to F15:
commit b598ac555c8fe67ffc39ac8ef25fe7e6b28ae3f2
Author: Eric Blake
Date: Thu May 26 08:18:46 2011 -0600
security: plug regression introduced in disk probe logic
wrong sizeof operand meant that security manager private data
was overlaying the allowDiskFormatProbing member of struct
_virSecurityManager. This reopens disk probing, which was
supposed to be prevented by the solution to CVE-2010-2238.
* src
Bugzilla
CVE-2011-2178 libvirt: regression introduced in disk probe logic
bugzilla·2011-06-01·CVSS 4.4
CVE-2011-2178 [MEDIUM] CVE-2011-2178 libvirt: regression introduced in disk probe logic
CVE-2011-2178 libvirt: regression introduced in disk probe logic
Regression introduced in commit d6623003 (v0.8.8) - using the wrong sizeof operand meant that security manager private data was overlaying the allowDiskFOrmatProbing member of struct _virSecurityManager. This reopens disk probing, which was supposed to be prevented by the solution to CVE-2010-2238.
Upstream patch:
https://www.redhat.com/archives/libvir-list/2011-May/msg01935.html
Discussion:
Created libvirt tracking bugs for this issue
Affects: fedora-15 [bug 709775]
Affects: fedora-rawhide [bug 709777]
---
Statement:
Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5 and 6 as we did not backport upstream commit d6623003.
---
verify pass on
kernel-2.6.32-156.e
Bugzilla
CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
bugzilla·2010-07-12·CVSS 4.4
CVE-2010-2237 [MEDIUM] CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=607810
Please note: this issue
Bugzilla
CVE-2010-2238 libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
bugzilla·2010-06-24·CVSS 4.4
CVE-2010-2238 [MEDIUM] CVE-2010-2238 libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
CVE-2010-2238 libvirt: ignoring defined disk backing store format when recursing into disk image backing stores
It was found that libvirt did not extract the defined disk backing store
format when recursing into disk image backing stores in the security
drivers. This could be possibly exploited by priviledged guest user to
access arbitrary files on the host.
Discussion:
This issue affects libvirt >= 0.7.2.
---
Statement:
Not vulnerable. This issue did not affect the version of libvirt as shipped with Red Hat Enterprise Linux 5.
---
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 613625]
---
libvirt-0.8.2-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
---
libvirt-0.8.2-1.fc12
http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044579.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://ubuntu.com/usn/usn-1008-1http://ubuntu.com/usn/usn-1008-2http://ubuntu.com/usn/usn-1008-3http://www.vupen.com/english/advisories/2010/2763https://bugzilla.redhat.com/show_bug.cgi?id=607811http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044579.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://ubuntu.com/usn/usn-1008-1http://ubuntu.com/usn/usn-1008-2http://ubuntu.com/usn/usn-1008-3http://www.vupen.com/english/advisories/2010/2763https://bugzilla.redhat.com/show_bug.cgi?id=607811
2010-08-19
Published