CVE-2010-2238: Medium severity oracle libvirt vulnerability
It was found that libvirt did not extract the defined disk backing store format when recursing into disk image backing stores in the security drivers. This could be possibly exploited by priviledged guest user to access arbitrary files on the host.
Other sources
Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2238?
CVE-2010-2238 is classified as a high-severity vulnerability due to its potential to allow privileged guest users to access arbitrary files on the host system.
How do I fix CVE-2010-2238?
To mitigate CVE-2010-2238, you should upgrade libvirt to version 0.8.3 or later, which contains the necessary security patches.
What versions of libvirt are affected by CVE-2010-2238?
CVE-2010-2238 affects libvirt versions from 0.7.2 to 0.8.2.
Who can exploit CVE-2010-2238?
CVE-2010-2238 can potentially be exploited by privileged guest users within the virtualized environment.
What is the impact of CVE-2010-2238?
The impact of CVE-2010-2238 is that it allows unauthorized access to sensitive files on the host from a compromised virtual machine.