CVE-2023-1386
published 2023-07-24CVE-2023-1386: A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.9th percentile
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | — | — |
| fedoraproject | fedora | — | — |
| github.com | hashicorp_vagrant | >= 0 < 2.4.0 | 2.4.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
ghsa·2023-10-28
CVE-2023-5834 [LOW] CWE-1386 HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
OSV
CVE-2023-1386: A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU
osv·2023-07-24·CVSS 7.8
CVE-2023-1386 [HIGH] CVE-2023-1386: A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
GHSA
GHSA-ppj8-867g-rgjr: A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU
ghsa_unreviewed·2023-07-24
CVE-2023-1386 [HIGH] CWE-281 GHSA-ppj8-867g-rgjr: A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Red Hat
QEMU: 9pfs: SUID/SGID bits not dropped on file write
vendor_redhat·2023-03-07·CVSS 3.3
CVE-2023-1386 [LOW] CWE-281 QEMU: 9pfs: SUID/SGID bits not dropped on file write
QEMU: 9pfs: SUID/SGID bits not dropped on file write
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within
Debian
CVE-2023-1386: qemu - A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU....
vendor_debian·2023·CVSS 3.3
CVE-2023-1386 [LOW] CVE-2023-1386: qemu - A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU....
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-1386https://bugzilla.redhat.com/show_bug.cgi?id=2223985https://github.com/advisories/GHSA-ppj8-867g-rgjrhttps://github.com/v9fs/linux/issues/29https://security.netapp.com/advisory/ntap-20230831-0005/https://access.redhat.com/security/cve/CVE-2023-1386https://bugzilla.redhat.com/show_bug.cgi?id=2223985https://github.com/advisories/GHSA-ppj8-867g-rgjrhttps://github.com/v9fs/linux/issues/29https://security.netapp.com/advisory/ntap-20230831-0005/
2023-07-24
Published