cbcvebase.
CVE-2020-14339
published 2020-12-03

CVE-2020-14339: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged…

PriorityP346high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.42%
33.7th percentile
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 6.6.0-1 (bookworm)libvirt 6.6.0-1 (bookworm)
redhatenterprise_linux
redhatlibvirt
redhatlibvirt>= 0 < 6.6.0-16.6.0-1
redhatlibvirt>= 0 < 6.6.0-16.6.0-1
redhatlibvirt>= 0 < 6.6.0-16.6.0-1
redhatlibvirt>= 0 < 6.6.0-16.6.0-1
redhatlibvirt>= 6.2.0 < 6.7.06.7.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.