Description
util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4137-1 | libvirt security update |
EUVD |
EUVD-2018-18511 | util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module. |
Ubuntu USN |
USN-3576-1 | libvirt vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:10:11.370Z
Reserved: 2018-02-06T00:00:00.000Z
Link: CVE-2018-6764
No data.
Status : Modified
Published: 2018-02-23T17:29:00.473
Modified: 2024-11-21T04:11:08.413
Link: CVE-2018-6764
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN