---
title: "CVE-2013-1766\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1766?format=md
keywords: index, follow
---

# CVE-2013-1766

Publication date 20 March 2013

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

libvirt 1.0.2 and earlier sets the group owner to kvm for device files,
which allows local users to write to these files via unspecified vectors.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1766?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libvirt | 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

Debian bug reports states this is a problem because the kvm group
is a general-purpose group and therefore changing device group ownership
exposes these devices to other groups on the system. The kvm group on Ubuntu
has been used since Ubuntu 10.10. Debian's solution is to update the
packaging to add a new libvirt-qemu groupi, have the libvirt-qemu user be
in the libvirt-qemu group as a secondary group, then use as a configure
option: --with-qemu-group=libvirt-qemu. This is too intrusive for a stable
release for an arguably marginal security gain.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1766)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1766)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1766)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1766)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2013-1766>
