Vulnerability record · CVE-2020-14339 · published 3 December 2020
CVE-2020-14339: Redhat libvirt vulnerability
Redhat · Libvirt
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Description
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1860069 | Issue TrackingPatchThird Party Advisory |
| https://security.gentoo.org/glsa/202101-22 | Third Party Advisory |
| https://security.gentoo.org/glsa/202210-06 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1860069 | Issue TrackingPatchThird Party Advisory |
| https://security.gentoo.org/glsa/202101-22 | Third Party Advisory |
| https://security.gentoo.org/glsa/202210-06 | Third Party Advisory |
Track CVE-2020-14339 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14339), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.