libvirt: Unintended access to /dev/mapper/control — GLSA 202101-22

A vulnerability in libvirt may allow root privilege escalation.

Affected packages

app-emulation/libvirt on all architectures
Affected versions < 6.7.0
Unaffected versions >= 6.7.0

Background

libvirt is a C toolkit for manipulating virtual machines.

Description

A file descriptor for /dev/mapper/control was insufficiently protected.

Impact

A local attacker may be able to escalate to root privileges.

Workaround

There is no known workaround at this time.

Resolution

All libvirt users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-emulation/libvirt-6.7.0"
 

References

Release date
January 26, 2021

Latest revision
January 26, 2021: 1

Severity
high

Exploitable
local

Bugzilla entries