CVE-2013-4311: Race Condition
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4311?
CVE-2013-4311 is classified as a high severity vulnerability allowing local users to bypass intended access restrictions.
How do I fix CVE-2013-4311?
To fix CVE-2013-4311, update your libvirt installation to version 1.0.5.6 or later, or to any patched version of 0.10.2 or 0.9.12.
Who is affected by CVE-2013-4311?
CVE-2013-4311 affects local users of libvirt versions prior to the specified updates, including certain Red Hat and Ubuntu distributions.
What type of vulnerability is CVE-2013-4311?
CVE-2013-4311 is a race condition vulnerability that allows local privilege escalation through PolkitUnixProcess.
Is there a workaround for CVE-2013-4311?
A temporary workaround for CVE-2013-4311 may include disabling the affected services or restricting access to vulnerable binaries until a patch is applied.