CVE-2011-2178

N/A Unknown
Published: August 10, 2011 Modified: April 29, 2026
View on NVD

Description

The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://libvirt.org/news.html
Source: secalert@redhat.com
http://www.ubuntu.com/usn/USN-1152-1
Source: secalert@redhat.com
http://libvirt.org/news.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://lists.opensuse.org/opensuse-updates/2011-06/msg00030.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-1152-1
Source: af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=709769
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://bugzilla.redhat.com/show_bug.cgi?id=709775
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.redhat.com/archives/libvir-list/2011-May/msg01935.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.3%
20th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

redhat