CVE-2020-14339

CWE-7729 documents7 sources
Severity
8.8HIGH
EPSS
0.1%
top 77.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateMay 24

Description

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages3 packages

NVDredhat/libvirt6.2.06.7.0
Debianlibvirt< 6.6.0-1+3
CVEListV5libvirtlibvirt 6.6.0

Also affects: Enterprise Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c772-g5j9-w9w8: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process2022-05-24
OSV
CVE-2020-14339: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process2020-12-03
CVEList
CVE-2020-14339: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process2020-12-03

📋Vendor Advisories

2
Red Hat
libvirt: leak of /dev/mapper/control into QEMU guests2020-07-17
Debian
CVE-2020-14339: libvirt - A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/...2020

💬Community

3
Bugzilla
CVE-2020-14339 libvirt: leak of /dev/mapper/control into QEMU guests [fedora-all]2020-09-21
Bugzilla
CVE-2020-14339 mingw-libvirt: libvirt: leak of /dev/mapper/control into QEMU guests [fedora-all]2020-09-21
Bugzilla
CVE-2020-14339 libvirt: leak of /dev/mapper/control into QEMU guests2020-07-23
CVE-2020-14339 (HIGH CVSS 8.8) | A flaw was found in libvirt | cvebase.io