REDHAT-BUG-1015228: High severity libvirt vulnerability
It was reported that virt-login-shell, an suid-root program, did not sanitize its environment variables or command-line interface arguments properly. This could allow a local user to overwrite arbitrary files as root and elevate their privileges.
This vulnerability was introduced in libvirt 1.1.2.
Acknowledgements:
Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1015228?
The severity of REDHAT-BUG-1015228 is considered high due to the potential for local privilege escalation.
How do I fix REDHAT-BUG-1015228?
To fix REDHAT-BUG-1015228, upgrade libvirt to a version later than 1.1.2 where the environment variable sanitization issue is addressed.
Who is affected by REDHAT-BUG-1015228?
Users running Red Hat libvirt version 1.1.2 or earlier are affected by REDHAT-BUG-1015228.
What are the implications of REDHAT-BUG-1015228?
The implications of REDHAT-BUG-1015228 include the risk of unauthorized file overwrites and potential root access for local users.
When was REDHAT-BUG-1015228 introduced?
REDHAT-BUG-1015228 was introduced in libvirt version 1.1.2.