QEMU: virtiofsd: potential privilege escalation via CVE-2018-13405
Published Aug 29, 2022
7.8
HIGHCVSS 3.1
EPSS 0.33%
Description
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This could allow a malicious unprivileged user inside the guest to gain access to resources accessible to the root group, potentially escalating their privileges within the guest. A malicious local user in the host might also leverage this unexpected executable file created by the guest to escalate their privileges on the host system.
Affected products
- Vendor n/a Product QEMU/virtiofsd Defaultunknown
Affected
- Fixed in qemu v6.2.0-7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | QEMU/virtiofsd | unknown | Affected
|
Configuration 2
- 8.0
No data.
Advanced Virtualization for RHEL 8.2.1
virt-devel:8.2-8020120220211042301.863bb0db
Fixed · RHSA-2022:0973
Advanced Virtualization for RHEL 8.2.1
virt:8.2-8020120220211042301.863bb0db
Fixed · RHSA-2022:0973
Advanced Virtualization for RHEL 8.4.0.EUS
virt-devel:av-8040020220210233846.522a0ee4
Fixed · RHSA-2022:0971
Advanced Virtualization for RHEL 8.4.0.EUS
virt:av-8040020220210233846.522a0ee4
Fixed · RHSA-2022:0971
Advanced Virtualization for RHEL 8.5.0.Z
virt-devel:av-8050020220210180726.c5368500
Fixed · RHSA-2022:0949
Advanced Virtualization for RHEL 8.5.0.Z
virt:av-8050020220210180726.c5368500
Fixed · RHSA-2022:0949
Red Hat Enterprise Linux 8
virt-devel:rhel-8050020220208234339.c5368500
Fixed · RHSA-2022:0886
Red Hat Enterprise Linux 8
virt:rhel-8050020220208234339.c5368500
Fixed · RHSA-2022:0886
Red Hat Enterprise Linux 8.4 Extended Update Support
virt-devel:rhel-8040020220214155039.522a0ee4
Fixed · RHSA-2022:0759
Red Hat Enterprise Linux 8.4 Extended Update Support
virt:rhel-8040020220214155039.522a0ee4
Fixed · RHSA-2022:0759
Red Hat Enterprise Linux 6
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Not affected
Red Hat Enterprise Linux 7
qemu-kvm-ma
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/qemu-kvm
Affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/qemu-kvm
Affected
Red Hat Enterprise Linux 9
qemu-kvm
Not affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
qemu-kvm-rhev
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Advanced Virtualization for RHEL 8.2.1 | virt-devel:8.2-8020120220211042301.863bb0db | Fixed | RHSA-2022:0973 |
| Advanced Virtualization for RHEL 8.2.1 | virt:8.2-8020120220211042301.863bb0db | Fixed | RHSA-2022:0973 |
| Advanced Virtualization for RHEL 8.4.0.EUS | virt-devel:av-8040020220210233846.522a0ee4 | Fixed | RHSA-2022:0971 |
| Advanced Virtualization for RHEL 8.4.0.EUS | virt:av-8040020220210233846.522a0ee4 | Fixed | RHSA-2022:0971 |
| Advanced Virtualization for RHEL 8.5.0.Z | virt-devel:av-8050020220210180726.c5368500 | Fixed | RHSA-2022:0949 |
| Advanced Virtualization for RHEL 8.5.0.Z | virt:av-8050020220210180726.c5368500 | Fixed | RHSA-2022:0949 |
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8050020220208234339.c5368500 | Fixed | RHSA-2022:0886 |
| Red Hat Enterprise Linux 8 | virt:rhel-8050020220208234339.c5368500 | Fixed | RHSA-2022:0886 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | virt-devel:rhel-8040020220214155039.522a0ee4 | Fixed | RHSA-2022:0759 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | virt:rhel-8040020220214155039.522a0ee4 | Fixed | RHSA-2022:0759 |
| Red Hat Enterprise Linux 6 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/qemu-kvm | Affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/qemu-kvm | Affected | n/a |
| Red Hat Enterprise Linux 9 | qemu-kvm | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | qemu-kvm-rhev | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of the `qemu-kvm` package as shipped with Red Hat Enterprise Linux 6 and 7. Virtio-fs is a fairly new feature (introduced upstream in QEMU v5.0) which is not built in Red Hat Enterprise Linux 6 and 7.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-0358 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2044863 Issue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15514 Advisory
- https://gitlab.com/qemu-project/qemu/-/commit/449e8171f96a6a944d1f3b7d3627ae059eae21ca PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0358
- https://security.netapp.com/advisory/ntap-20221007-0008/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0358
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0358 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2044863 | Issue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15514 | Advisory | |
| https://gitlab.com/qemu-project/qemu/-/commit/449e8171f96a6a944d1f3b7d3627ae059eae21ca | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0358 | ||
| https://security.netapp.com/advisory/ntap-20221007-0008/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0358 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data