CVE-2013-6456
published 2014-04-15CVE-2013-6456: The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and…
PriorityP427medium5.8CVSS 2.0
AVAACMAuSCNIPAC
EPSS
0.57%
43.5th percentile
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.3-1 (bookworm) | libvirt 1.2.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.3-1 | 1.2.3-1 |
| redhat | libvirt | >= 0 < 1.2.3-1 | 1.2.3-1 |
| redhat | libvirt | >= 0 < 1.2.3-1 | 1.2.3-1 |
| redhat | libvirt | >= 0 < 1.2.3-1 | 1.2.3-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:A/AC:M/Au:S/C:N/I:P/A:C
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-05-07·CVSS 5.8
CVE-2013-6456 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled symlinks when using the
LXC driver. An attacker could possibly use this issue to delete host
devices, create arbitrary nodes, and shutdown or power off the host.
(CVE-2013-6456)
Marian Krcmarik discovered that libvirt incorrectly handled seamless SPICE
migrations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2013-7336)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
libvirt: unsafe usage of paths under /proc/$PID/root
vendor_redhat·2013-12-17·CVSS 5.8
CVE-2013-6456 [MEDIUM] libvirt: unsafe usage of paths under /proc/$PID/root
libvirt: unsafe usage of paths under /proc/$PID/root
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Wi
Debian
CVE-2013-6456: libvirt - The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local us...
vendor_debian·2013·CVSS 5.8
CVE-2013-6456 [MEDIUM] CVE-2013-6456: libvirt - The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local us...
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid: resolved (fixed in 1.2.3-1)
trixie: resolved (fixed in 1.2.3-1)
GHSA
GHSA-4c8j-w686-c2jw: The LXC driver (lxc/lxc_driver
ghsa_unreviewed·2022-05-17
CVE-2013-6456 [MEDIUM] CWE-59 GHSA-4c8j-w686-c2jw: The LXC driver (lxc/lxc_driver
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
OSV
CVE-2013-6456: The LXC driver (lxc/lxc_driver
osv·2014-04-15·CVSS 5.8
CVE-2013-6456 [MEDIUM] CVE-2013-6456: The LXC driver (lxc/lxc_driver
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root [fedora-all]
bugzilla·2014-01-05·CVSS 5.8
CVE-2013-6456 [MEDIUM] CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root [fedora-all]
CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root
bugzilla·2014-01-05·CVSS 5.8
CVE-2013-6456 [MEDIUM] CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root
CVE-2013-6456 libvirt: unsafe usage of paths under /proc/$PID/root
Eric Blake from Red Hat notes:
The LXC driver will open paths under /proc/$PID/root for some operations it performs on running guests. For the virDomainShutdown and virDomainReboot APIs it will use this to access the /dev/initctl path in the container. For the virDomainDeviceAttach / virDomainDeviceDettach APIs it will use this to create device nodes in the container's /dev filesystem. If any of the path components under control of the container are symlinks the container can cause the libvirtd daemon to access the incorrect files.
Impact
A container can cause the administrator to shutdown or reboot the host OS if /dev/initctl in the container is made to be an absolute symlink back to itself or /run/initctl. A container
Bugzilla
CVE-2013-6456 libvirt: vulnerability in virInitctlSetRunLevel [rhel-7.0]
bugzilla·2013-12-20·CVSS 5.8
CVE-2013-6456 [MEDIUM] CVE-2013-6456 libvirt: vulnerability in virInitctlSetRunLevel [rhel-7.0]
CVE-2013-6456 libvirt: vulnerability in virInitctlSetRunLevel [rhel-7.0]
Description of problem:
Public debian bug #732394 points out a vulnerability where a malicious guest can use symlinks to cause the LXC driver to manipulate unintended files in the host during the virDomainShutdown, virDomainReboot, virDomainDeviceAttach, and virDomainDeviceDettach APIs.
The libvirt-security list has been notified (private archives: https://www.redhat.com/mailman/private/libvirt-security/2013-December/msg00018.html), and we are now awaiting assignment of a CVE to cover this issue. Public patches are underway for the virDomainShutdown/virDomainReboot issues (v4 is incomplete, v5 not posted yet: https://www.redhat.com/archives/libvir-list/2013-December/msg01182.html), at the time of this BZ, the virDom
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=5fc590ad9f4http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/129199.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00004.htmlhttp://secunia.com/advisories/56187http://secunia.com/advisories/56215http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2013/0018.htmlhttp://www.securityfocus.com/bid/65743https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732394https://bugzilla.redhat.com/show_bug.cgi?id=1045643http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=5fc590ad9f4http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-February/129199.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00004.htmlhttp://secunia.com/advisories/56187http://secunia.com/advisories/56215http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2013/0018.htmlhttp://www.securityfocus.com/bid/65743https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732394https://bugzilla.redhat.com/show_bug.cgi?id=1045643
2014-04-15
Published