Vulnerability Description
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Libvirt | < 7.5.0 |
| Redhat | Openshift Container Platform | 4.8 |
| Redhat | Enterprise Linux | 8.0 |
| Netapp | Ontap Select Deploy Administration Utility | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2021:3631Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1977726Issue TrackingVendor Advisory
- https://gitlab.com/libvirt/libvirt/-/commit/15073504dbb624d3f6c911e85557019d3620PatchThird Party Advisory
- https://gitlab.com/libvirt/libvirt/-/issues/153ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://security.gentoo.org/glsa/202210-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220331-0010/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2021:3631Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1977726Issue TrackingVendor Advisory
- https://gitlab.com/libvirt/libvirt/-/commit/15073504dbb624d3f6c911e85557019d3620PatchThird Party Advisory
- https://gitlab.com/libvirt/libvirt/-/issues/153ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00000.html
- https://security.gentoo.org/glsa/202210-06Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220331-0010/Third Party Advisory
FAQ
What is CVE-2021-3631?
CVE-2021-3631 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the brea...
How severe is CVE-2021-3631?
CVE-2021-3631 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3631?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Libvirt, Redhat Openshift Container Platform, Redhat Enterprise Linux, Netapp Ontap Select Deploy Administration Utility.