| Reported on: | 20130805 |
|---|---|
| Published on: | 20130805 |
| Fixed on: | 20130829 |
| Reported by: | Eric Blake |
|---|---|
| Patched by: | Eric Blake |
When parsing the process security label for the DAC driver the list of supplementary groups was not initialized. This would lead to the QEMU process inheriting supplementary groups from the libvirtd daemon.
The QEMU processes inherit supplementary groups libvirtd which may lead to it being granted access to in appropriate resources
Ensure a MAC driver such as SELinux or AppArmour is used to confine the QEMU processes, so that a compromised QEMU cannot take advantage of the inherited supplementary groups.