Libvirt Security Restriction Bypass Vulnerability (CVE-2018-6764)
Libvirt Security Restriction Bypass Vulnerability (CVE-2018-6764)
Release date:
Updated on:
Affected Systems:
Libvirt
Description:
CVE (CAN) ID: CVE-2018-6764
The Libvirt library is a Linux API for implementing Linux virtualization. It supports various hypervisors, including Xen and KVM, QEMU, and some virtual products for other operating systems.
Libvirt util/virlog. c does not properly determine the host name in the LXC container startup. This vulnerability allows local users to bypass the protection mechanism of the target container and execute arbitrary commands.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Libvirt
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libvirt.org/index.html
Https://www.redhat.com/archives/libvir-list/2018-February/msg00239.html
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151423.htm