cbcvebase.
CVE-2022-0358
published 2022-08-29

CVE-2022-0358: A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.33%
24.7th percentile
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianqemu< qemu 1:7.0+dfsg-1 (bookworm)qemu 1:7.0+dfsg-1 (bookworm)
msrcazl3_qemu_6.2.0-18_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_qemu_6.2.0-5_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0
qemuqemu< 6.2.0-76.2.0-7
qemuqemu>= 0 < 1:5.2+dfsg-11+deb11u21:5.2+dfsg-11+deb11u2
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:7.0+dfsg-11:7.0+dfsg-1
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.391:2.11+dfsg-1ubuntu7.39
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.401:2.11+dfsg-1ubuntu7.40
qemuqemu>= 0 < 1:4.2-3ubuntu6.211:4.2-3ubuntu6.21
qemuqemu>= 0 < 1:4.2-3ubuntu6.231:4.2-3ubuntu6.23
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.21:6.2+dfsg-2ubuntu6.2
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.