The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libvirt | Jul 30, 2024 | Aug 10, 2011 |
| Gentoo Linux | — | Upgrade app-emulation/libvirt. | Oct 30, 2017 | Aug 10, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 31, 2011 |
| Suse | — | Upgrade libvirtUpgrade libvirt-clientUpgrade libvirt-pythonUpgrade libvirt-docUpgrade libvirt-devel | Dec 12, 2013 | Aug 10, 2011 |
| Ubuntu | — | Upgrade libvirt0Upgrade libvirt-bin | Nov 8, 2024 | Aug 10, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub