Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0358

Опубликовано: 25 янв. 2022
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

Отчет

This issue does not affect the versions of the qemu-kvm package as shipped with Red Hat Enterprise Linux 6 and 7. Virtio-fs is a fairly new feature (introduced upstream in QEMU v5.0) which is not built in Red Hat Enterprise Linux 6 and 7.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmAffected
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevOut of support scope
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevOut of support scope
Advanced Virtualization for RHEL 8.2.1virtFixedRHSA-2022:097321.03.2022
Advanced Virtualization for RHEL 8.2.1virt-develFixedRHSA-2022:097321.03.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-273
https://bugzilla.redhat.com/show_bug.cgi?id=2044863QEMU: virtiofsd: potential privilege escalation via CVE-2018-13405

EPSS

Процентиль: 3%
0.00018
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

CVSS3: 7.8
nvd
почти 3 года назад

A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

CVSS3: 7.8
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 3 года назад

A flaw was found in the QEMU virtio-fs shared file system daemon (virt ...

rocky
больше 3 лет назад

Moderate: virt:rhel and virt-devel:rhel security update

EPSS

Процентиль: 3%
0.00018
Низкий

7 High

CVSS3