libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
CVSS Details
- CVSS 3.1 Base Score: 7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade spice-gtk.Upgrade polkitUpgrade libvirt | Aug 30, 2017 | Oct 3, 2013 |
| Centos_linux | — | Upgrade libvirt-develUpgrade libvirt-clientUpgrade libvirt-lock-sanlockUpgrade libvirtUpgrade libvirt-python | Dec 1, 2016 | Oct 3, 2013 |
| Debian | — | Upgrade libvirt | Jul 30, 2024 | Oct 3, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/libvirt.Upgrade sys-apps/systemd.Upgrade net-print/hplip.Upgrade net-misc/spice-gtk.Upgrade sys-auth/polkit. | Oct 30, 2017 | Oct 3, 2013 |
| Oracle_linux | — | Upgrade libvirt-clientUpgrade libvirtUpgrade libvirt-pythonUpgrade libvirt-lock-sanlockUpgrade libvirt-devel | Oct 16, 2024 | Oct 3, 2013 |
| Suse | — | Upgrade libvirt-devel-32bitUpgrade libvirt-clientUpgrade libvirt-client-32bitUpgrade libvirt-develUpgrade libvirt-pythonUpgrade libvirtUpgrade libvirt-lock-sanlockUpgrade libvirt-doc | Dec 12, 2013 | Oct 3, 2013 |
| Ubuntu | — | Upgrade libvirt-binUpgrade libvirt0 | Nov 8, 2024 | Oct 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub