SB2021030416 - Red Hat Enterprise Linux 8 update for the virt:rhel and virt-devel:rhel modules
Published: March 4, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2020-35517)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists within the virtio-fs shared file system daemon (virtiofsd). A remote privileged user of the guest operating system can create device special file in the shared directory and use it to r/w access host devices.
Remediation
Install update from vendor's website.