|
|
| |
|
| |
libvirt: group updating error
| Package(s): | libvirt |
CVE #(s): | CVE-2013-4291
|
| Created: | September 12, 2013 |
Updated: | October 2, 2013 |
| Description: |
From the Red Hat bug:
Upstream Commit 29fe5d7 (released in 1.1.1) introduced a latent problem for any caller of virSecurityManagerSetProcessLabel and where the domain already had a uid:gid label to be parsed. Such a setup would collect the list of supplementary groups during virSecurityManagerPreFork, but then ignores that information, and thus fails to call setgroups() to adjust the supplementary groups of the process. |
| Alerts: |
|
( Log in to post comments)
|
|
|