CVE-2021-3631

EUVD-2021-26933
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
redhatlibvirt
𝑥
< 7.5.0
redhatopenshift_container_platform
4.8
redhatenterprise_linux
8.0
netappontap_select_deploy_administration_utility
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libvirt
bookworm
9.0.0-4+deb12u1
fixed
bullseye
7.0.0-3+deb11u3
fixed
sid
10.9.0-1
fixed
stretch
no-dsa
trixie
10.9.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libvirt
bionic
Fixed 4.0.0-1ubuntu8.21
released
focal
Fixed 6.0.0-0ubuntu8.16
released
groovy
ignored
hirsute
ignored
impish
not-affected
jammy
Fixed 7.6.0-0ubuntu3
released
kinetic
Fixed 7.6.0-0ubuntu3
released
lunar
Fixed 7.6.0-0ubuntu3
released
mantic
Fixed 7.6.0-0ubuntu3
released
noble
Fixed 7.6.0-0ubuntu3
released
trusty
needs-triage
xenial
needs-triage