CVE-2021-3631: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Other sources
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw may allow one exploited guest to access files labelled for another guest, thus breaking out of sVirt confinement.
Upstream issue: https://gitlab.com/libvirt/libvirt/-/issues/153
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in libvirt?
The vulnerability ID is CVE-2021-3631.
What is the severity level of CVE-2021-3631?
The severity level of CVE-2021-3631 is low.
How does CVE-2021-3631 affect confidentiality?
CVE-2021-3631 poses a threat to confidentiality.
What software versions are affected by CVE-2021-3631?
Versions 6.0.0-0ubuntu8.16, 7.6.0-1, 4.0.0-1ubuntu8.21, 7.6.0-0ubuntu3, 7.6.0-0ubuntu3, 7.6.0-0ubuntu3, 7.5.0, 9.0.0-4, and 9.7.0-1 of libvirt are affected by CVE-2021-3631.
How can I fix CVE-2021-3631?
Run the recommended updates for the affected libvirt versions.