First published: Mon Mar 01 2021(Updated: )
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qemu | <5.2.50 | 5.2.50 |
QEMU qemu | >=5.0.0<5.2.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20263 is a vulnerability found in the virtio-fs shared file system daemon (virtiofsd) of QEMU.
The vulnerability may allow an attacker to create a modified, privileged executable in the guest system.
Update the QEMU package to version 5.2.50 or apply the provided remedy.
The severity level of CVE-2021-20263 is low, with a CVSS score of 3.3.
The CWE of CVE-2021-20263 is CWE-281.