CVE-2021-3631

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
redhatlibvirt
𝑥
< 7.5.0
redhatopenshift_container_platform
4.8
redhatenterprise_linux
8.0
netappontap_select_deploy_administration_utility
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libvirt
bullseye
7.0.0-3+deb11u3
fixed
stretch
no-dsa
bookworm
9.0.0-4+deb12u1
fixed
sid
10.9.0-1
fixed
trixie
10.9.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libvirt
noble
Fixed 7.6.0-0ubuntu3
released
mantic
Fixed 7.6.0-0ubuntu3
released
lunar
Fixed 7.6.0-0ubuntu3
released
kinetic
Fixed 7.6.0-0ubuntu3
released
jammy
Fixed 7.6.0-0ubuntu3
released
impish
not-affected
hirsute
ignored
groovy
ignored
focal
Fixed 6.0.0-0ubuntu8.16
released
bionic
Fixed 4.0.0-1ubuntu8.21
released
xenial
needs-triage
trusty
needs-triage