libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
CVSS Details
- CVSS 3.1 Base Score: 4.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade libvirt-clientUpgrade libvirt-develUpgrade libvirt-lock-sanlockUpgrade libvirtUpgrade libvirt-python | Dec 1, 2016 | Jun 16, 2012 |
| Debian | — | Upgrade libvirt | Jul 30, 2024 | Jun 17, 2012 |
| Oracle_linux | — | Upgrade libvirtUpgrade libvirt-pythonUpgrade libvirt-clientUpgrade libvirt-lock-sanlockUpgrade libvirt-devel | Oct 16, 2024 | Jun 17, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 28, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub