Loading HuntDB...

GHSA-c772-g5j9-w9w8

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Related CVEs

Key Information

GHSA ID
GHSA-c772-g5j9-w9w8
Published
May 24, 2022 5:35 PM
Last Modified
October 16, 2022 7:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.