Bug 837530 (CVE-2013-4291) - VUL-0: CVE-2013-4291: libvirt: provide supplemental groups even when parsing label
Summary: VUL-0: CVE-2013-4291: libvirt: provide supplemental groups even when parsing ...
Status: RESOLVED FIXED
Alias: CVE-2013-4291
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:54477:moderate maint:re...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-08-29 14:19 UTC by Marcus Meissner
Modified: 2015-03-05 14:47 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-08-29 14:19:02 UTC
not yet public, discussed on libvirt security list

Please keep inside SUSE!

On Fri, Aug 23, 2013 at 09:58:07AM -0600, Eric Blake wrote:
> Commit 29fe5d7 (first in 1.1.1) introduced a latent problem for
> any caller of virSecurityManagerSetProcessLabel and where the
> domain already had a uid:gid label to be parsed.  Such a setup
> would collect the list of supplementary groups during
> virSecurityManagerPreFork, but then ignores that information,
> and thus fails to call setgroups() to adjust the supplementary
> groups of the process.

CVE-2013-4291


final patch still in discussion


are we affected by this?
Comment 1 James Fehlig 2013-08-29 15:18:32 UTC
(In reply to comment #0)
> are we affected by this?

Only in Factory.
Comment 2 James Fehlig 2013-08-29 16:38:58 UTC
libvirt 1.1.2, which will contain a fix for this issue, will be released early next week.  I'll update Factory then, instead of wasting time backporting patches to 1.1.1
Comment 3 Swamp Workflow Management 2013-08-29 22:00:32 UTC
bugbot adjusting priority
Comment 4 James Fehlig 2013-09-04 04:21:07 UTC
Submitted libvirt 1.1.2 to Factory, SR#197361.
Comment 5 Bernhard Wiedemann 2013-09-04 05:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (837530) was mentioned in
https://build.opensuse.org/request/show/197361 Factory / libvirt
Comment 6 Alexander Bergmann 2013-09-20 15:32:59 UTC
Closing bug as only Factory was affected and was already fixed.
Comment 8 Swamp Workflow Management 2013-11-08 20:00:25 UTC
Update released for: libvirt, libvirt-client, libvirt-client-32bit, libvirt-client-x86, libvirt-debuginfo, libvirt-debugsource, libvirt-devel, libvirt-devel-32bit, libvirt-doc, libvirt-lock-sanlock, libvirt-python
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP3 (i386, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)