CVE-2022-0358
Vulnerability Summary
Timeline
Description
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.33%• Percentile: 27%
Techniques & Countermeasures
- CWE-273•Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Affected Systems
- debian•qemu
< 1:5.2+dfsg-11+deb11u2 | < 1:7.0+dfsg-1 | < 1:7.0+dfsg-1 | < 1:7.0+dfsg-1
- qemu•qemu
< 6.2.0-7
- redhat•enterprise_linux
8.0
References (5)
- https://bugzilla.redhat.com/show_bug.cgi?id=2044863
- https://gitlab.com/qemu-project/qemu/-/commit/449e8171f96a6a944d1f3b7d3627ae059eae21ca
- https://access.redhat.com/security/cve/CVE-2022-0358
- https://security.netapp.com/advisory/ntap-20221007-0008/
- https://security-tracker.debian.org/tracker/CVE-2022-0358