CVE-2010-2224: Low severity red hat enterprise virtualization manager vulnerability
It was found that Red Hat Enterprise Virtualization Manager did not correctly pass the postzero parameter for deleted volumes after snapshot merging. This resulted in such volumes not being securely deleted as expected. A guest user in a new, raw virtual machine (VM), created in a data domain that has had VMs deleted from it, could use this flaw to read limited data from those deleted VMs, potentially disclosing sensitive information. (CVE-2010-2224)
Other sources
The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2224?
CVE-2010-2224 is considered a moderate severity vulnerability due to its potential for data exposure.
How do I fix CVE-2010-2224?
To mitigate CVE-2010-2224, update to a later version of Red Hat Enterprise Virtualization Manager where the issue has been resolved.
Who is affected by CVE-2010-2224?
CVE-2010-2224 affects users of Red Hat Enterprise Virtualization Manager version 2.1 and earlier.
What type of vulnerability is CVE-2010-2224?
CVE-2010-2224 is a security vulnerability related to improper handling of deleted volumes after snapshot merging.
Can CVE-2010-2224 lead to data loss?
CVE-2010-2224 does not directly cause data loss but may lead to sensitive data not being securely deleted.