CVE-2021-20263
published 2021-03-09CVE-2021-20263: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.38%
29.7th percentile
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:5.2+dfsg-9 (bookworm) | qemu 1:5.2+dfsg-9 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:5.2+dfsg-9 | 1:5.2+dfsg-9 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-9 | 1:5.2+dfsg-9 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-9 | 1:5.2+dfsg-9 |
| qemu | qemu | >= 0 < 1:5.2+dfsg-9 | 1:5.2+dfsg-9 |
| qemu | qemu | >= 5.0.0 < 5.2.50 | 5.2.50 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
QEMU: virtiofsd: 'security.capabilities' is not dropped with xattrmap option
vendor_redhat·2021-03-01·CVSS 3.3
CVE-2021-20263 [LOW] CWE-281 QEMU: virtiofsd: 'security.capabilities' is not dropped with xattrmap option
QEMU: virtiofsd: 'security.capabilities' is not dropped with xattrmap option
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their priv
Debian
CVE-2021-20263: qemu - A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU....
vendor_debian·2021·CVSS 3.3
CVE-2021-20263 [LOW] CVE-2021-20263: qemu - A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU....
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
Scope: local
bookworm: resolved (fixed in 1:5.2+dfsg-9)
bullseye: resolved (fixed in 1:5.2+dfsg-9)
forky: resolved (fixed in 1:5.2+dfsg-9)
sid: resolved (fixed in 1:5.2+dfsg-9)
trixie: resolved (fixed in 1:5.2+dfsg-9)
GHSA
GHSA-349h-phx6-ghfj: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU
ghsa_unreviewed·2022-05-24
CVE-2021-20263 [LOW] CWE-281 GHSA-349h-phx6-ghfj: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
OSV
CVE-2021-20263: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU
osv·2021-03-09·CVSS 3.3
CVE-2021-20263 [LOW] CVE-2021-20263: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1933668https://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210507-0002/https://www.openwall.com/lists/oss-security/2021/03/08/1https://bugzilla.redhat.com/show_bug.cgi?id=1933668https://security.gentoo.org/glsa/202208-27https://security.netapp.com/advisory/ntap-20210507-0002/https://www.openwall.com/lists/oss-security/2021/03/08/1
2021-03-09
Published