VulnerabilityModified
CVE-2021-3631
This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement.
MEDIUM 6.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- redhat/libvirt · redhat/openshift container platform · redhat/enterprise linux · netapp/ontap select deploy administration utility
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2021:3631Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1977726Issue Tracking, Vendor Advisory
- https://gitlab.com/libvirt/libvirt/-/commit/15073504dbb624d3f6c911e85557019d3620fdb2Patch, Third Party Advisory
- https://gitlab.com/libvirt/libvirt/-/issues/153Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://security.gentoo.org/glsa/202210-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220331-0010/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2021:3631Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1977726Issue Tracking, Vendor Advisory
- https://gitlab.com/libvirt/libvirt/-/commit/15073504dbb624d3f6c911e85557019d3620fdb2Patch, Third Party Advisory
- https://gitlab.com/libvirt/libvirt/-/issues/153Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://security.gentoo.org/glsa/202210-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220331-0010/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.