CVE-2018-6764
published 2018-02-23CVE-2018-6764: util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
25.3th percentile
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libvirt | < libvirt 4.0.0-2 (bookworm) | libvirt 4.0.0-2 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | libvirt | >= 0 < 4.0.0-2 | 4.0.0-2 |
| redhat | libvirt | >= 0 < 4.0.0-2 | 4.0.0-2 |
| redhat | libvirt | >= 0 < 4.0.0-2 | 4.0.0-2 |
| redhat | libvirt | >= 0 < 4.0.0-2 | 4.0.0-2 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.26 | 1.2.2-0ubuntu13.1.26 |
| redhat | libvirt | >= 0 < 1.3.1-1ubuntu10.19 | 1.3.1-1ubuntu10.19 |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37fp-qc5g-vpxr: util/virlog
ghsa_unreviewed·2022-05-13
CVE-2018-6764 [HIGH] CWE-346 GHSA-37fp-qc5g-vpxr: util/virlog
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
OSV
CVE-2018-6764: util/virlog
osv·2018-02-23·CVSS 7.8
CVE-2018-6764 [HIGH] CVE-2018-6764: util/virlog
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
OSV
libvirt vulnerabilities
osv·2018-02-20·CVSS 9.8
CVE-2016-5008 [CRITICAL] libvirt vulnerabilities
libvirt vulnerabilities
Vivian Zhang and Christoph Anton Mitterer discovered that libvirt
incorrectly disabled password authentication when the VNC password was set
to an empty string. A remote attacker could possibly use this issue to
bypass authentication, contrary to expectations. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008)
Daniel P. Berrange discovered that libvirt incorrectly handled validating
SSL/TLS certificates. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 17.10.
(CVE-2017-1000256)
Daniel P. Berrange and Peter Krempa discovered that libvirt incorrectly
handled large QEMU replies. An attacker could possibly use this issue to
cause libvirt to crash, resulting in a denial of ser
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2018-02-20·CVSS 9.8
CVE-2016-5008 [CRITICAL] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Vivian Zhang and Christoph Anton Mitterer discovered that libvirt
incorrectly disabled password authentication when the VNC password was set
to an empty string. A remote attacker could possibly use this issue to
bypass authentication, contrary to expectations. This issue only affected
Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008)
Daniel P. Berrange discovered that libvirt incorrectly handled validating
SSL/TLS certificates. A remote attacker could possibly use this issue to
obtain sensitive information. This issue only affected Ubuntu 17.10.
(CVE-2017-1000256)
Daniel P. Berrange and Peter Krempa discovered that libvirt incorrectly
handled large QEMU replies. An attacker could possibly use th
Red Hat
libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
vendor_redhat·2018-02-05·CVSS 7.8
CVE-2018-6764 [HIGH] CWE-179 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 8) - Not affected
Package: libvirt (Red Hat Storage 3) - Not affected
Debian
CVE-2018-6764: libvirt - util/virlog.c in libvirt does not properly determine the hostname on LXC contain...
vendor_debian·2018·CVSS 7.8
CVE-2018-6764 [HIGH] CVE-2018-6764: libvirt - util/virlog.c in libvirt does not properly determine the hostname on LXC contain...
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
Scope: local
bookworm: resolved (fixed in 4.0.0-2)
bullseye: resolved (fixed in 4.0.0-2)
forky: resolved (fixed in 4.0.0-2)
sid: resolved (fixed in 4.0.0-2)
trixie: resolved (fixed in 4.0.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
bugzilla·2018-02-07·CVSS 7.8
CVE-2018-6764 [HIGH] CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: t
Bugzilla
CVE-2018-6764 mingw-libvirt: libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
bugzilla·2018-02-07·CVSS 7.8
CVE-2018-6764 [HIGH] CVE-2018-6764 mingw-libvirt: libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
CVE-2018-6764 mingw-libvirt: libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit me
Bugzilla
CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
bugzilla·2018-02-02·CVSS 7.8
CVE-2018-6764 [HIGH] CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
CVE-2018-6764 libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init
libvirt_lxc resolves a host name after the guest filesystem is mounted but before the init from it is executed. That in turn causes glibc to load libnss_dns.so and it ends up being loaded from the guest tree, making it possible for the guest to inject executable code before the host filesystem is umounted and file handles closed. That has potential security implications.
Discussion:
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1542815]
Created mingw-libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1542814]
---
Upsptream fix is in git as:
commit 759b4d1b0fe5f4d84d98b99153dfa7ac289dd167
Author: Lubomir Rintel
Date: Sat Jan 27 23:43:58
http://www.ubuntu.com/usn/USN-3576-1https://access.redhat.com/errata/RHSA-2018:3113https://www.debian.org/security/2018/dsa-4137https://www.redhat.com/archives/libvir-list/2018-February/msg00239.htmlhttp://www.ubuntu.com/usn/USN-3576-1https://access.redhat.com/errata/RHSA-2018:3113https://www.debian.org/security/2018/dsa-4137https://www.redhat.com/archives/libvir-list/2018-February/msg00239.html
2018-02-23
Published