A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5133-1 qemu security update
EUVD EUVD EUVD-2022-15514 A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
Ubuntu USN Ubuntu USN USN-5307-1 QEMU vulnerabilities
Ubuntu USN Ubuntu USN USN-5489-1 QEMU vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-02T23:25:40.534Z

Reserved: 2022-01-25T00:00:00

Link: CVE-2022-0358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-29T15:15:09.310

Modified: 2024-11-21T06:38:27.123

Link: CVE-2022-0358

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-01-25T00:00:00Z

Links: CVE-2022-0358 - Bugzilla

cve-icon OpenCVE Enrichment

No data.