cbcvebase.
CVE-2022-0358
published 2022-08-29

CVE-2022-0358: A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.0+dfsg-1 (bookworm)qemu 1:7.0+dfsg-1 (bookworm)
msrcazl3_qemu_6.2.0-18_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_qemu_6.2.0-5_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0
qemuqemu< 6.2.0-76.2.0-7
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u21:5.2+dfsg-11+deb11u2
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.391:2.11+dfsg-1ubuntu7.39
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.401:2.11+dfsg-1ubuntu7.40
qemuqemu>= 0 < 1:4.2-3ubuntu6.211:4.2-3ubuntu6.21
qemuqemu>= 0 < 1:4.2-3ubuntu6.231:4.2-3ubuntu6.23
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.21:6.2+dfsg-2ubuntu6.2
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH