SB2021030823 - Advanced Virtualization for RHEL 8 update for the virt:8.2 and virt-devel:8.2 modules
Published: March 8, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2020-35517)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists within the virtio-fs shared file system daemon (virtiofsd). A remote privileged user of the guest operating system can create device special file in the shared directory and use it to r/w access host devices.
Remediation
Install update from vendor's website.