Red Hat libvirt, possibly 0.7.2 through 0.8.2, recurses into disk-image backing stores without extracting the defined disk backing-store format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libvirt | Jul 30, 2024 | Aug 19, 2010 |
| Suse | — | Upgrade libvirt-clientUpgrade libvirt-docUpgrade libvirt-pythonUpgrade libvirtUpgrade libvirt-devel | Feb 17, 2015 | Aug 19, 2010 |
| Ubuntu | — | Upgrade libvirt0Upgrade libvirt-bin | Nov 8, 2024 | Aug 19, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub