CVE-2020-35517
published 2021-01-28CVE-2020-35517: A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to…
PriorityP338high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.52%
41.2th percentile
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:5.2+dfsg-5 (bookworm) | qemu 1:5.2+dfsg-5 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-5 | 1:5.2+dfsg-5 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-5 | 1:5.2+dfsg-5 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-5 | 1:5.2+dfsg-5 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-5 | 1:5.2+dfsg-5 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
| qemu | qemu | 5.0.0 – 5.2.50 | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jgxm-7vmw-79h7: A flaw was found in qemu
ghsa_unreviewed·2022-05-24
CVE-2020-35517 [HIGH] CWE-269 GHSA-jgxm-7vmw-79h7: A flaw was found in qemu
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 [LOW] qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
OSV
CVE-2020-35517: A flaw was found in qemu
osv·2021-01-28·CVSS 8.2
CVE-2020-35517 [HIGH] CVE-2020-35517: A flaw was found in qemu
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 2.3
CVE-2021-3594 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu di
Red Hat
QEMU: virtiofsd: potential privileged host device access from guest
vendor_redhat·2021-01-21·CVSS 8.2
CVE-2020-35517 [HIGH] CWE-269 QEMU: virtiofsd: potential privileged host device access from guest
QEMU: virtiofsd: potential privileged host device access from guest
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: This issue does not affect the version of the qemu-kvm package as shipped with the Red Hat Enterprise Linux 5,
Debian
CVE-2020-35517: qemu - A flaw was found in qemu. A host privilege escalation issue was found in the vir...
vendor_debian·2020·CVSS 8.2
CVE-2020-35517 [HIGH] CVE-2020-35517: qemu - A flaw was found in qemu. A host privilege escalation issue was found in the vir...
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-5)
bullseye: resolved (fixed in 1:5.2+dfsg-5)
forky: resolved (fixed in 1:5.2+dfsg-5)
sid: resolved (fixed in 1:5.2+dfsg-5)
trixie: resolved (fixed in 1:5.2+dfsg-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1915823https://github.com/qemu/qemu/commit/ebf101955ce8f8d72fba103b5151115a4335de2chttps://lists.gnu.org/archive/html/qemu-devel/2021-01/msg05461.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210312-0002/https://www.openwall.com/lists/oss-security/2021/01/22/1https://bugzilla.redhat.com/show_bug.cgi?id=1915823https://github.com/qemu/qemu/commit/ebf101955ce8f8d72fba103b5151115a4335de2chttps://lists.gnu.org/archive/html/qemu-devel/2021-01/msg05461.htmlhttps://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210312-0002/https://www.openwall.com/lists/oss-security/2021/01/22/1
2021-01-28
Published