Alpine: multiple libvirt packages: security update to 6.6.0-r0

high Tenable Cloud Security Plugin ID 405355

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU
process. This file descriptor allows for privileged operations to happen against the device-mapper on the
host. This flaw allows a malicious guest user or process to perform operations outside of their standard
permissions, potentially causing serious damage to the host operating system. The highest threat from this
vulnerability is to confidentiality, integrity, as well as system availability. (CVE-2020-14339)

See Also

https://security.alpinelinux.org/vuln/CVE-2020-14339

Plugin Details

Severity: High

ID: 405355

Version: Revision 1.29

Type: Local

Published: 10/31/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 95.11

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-14339

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/1/2020

Reference Information

CVE: CVE-2020-14339