CVE-2021-20263

Related Vulnerabilities: CVE-2021-20263  

A flaw was found in QEMU. The new '-o xattrmap' option in virtiofsd sometimes causes the 'security.capability' xattr in the guest to not drop on write, potentially leading to a modified, privileged executable. The highest threat from this vulnerability is to integrity.

Description

A flaw was found in QEMU. The new '-o xattrmap' option in virtiofsd sometimes causes the 'security.capability' xattr in the guest to not drop on write, potentially leading to a modified, privileged executable. The highest threat from this vulnerability is to integrity.

Additional Information

  • Bugzilla 1933668: CVE-2021-20263 QEMU: virtiofsd: 'security.capabilities' is not dropped with xattrmap option
  • CWE-281: Improper Preservation of Permissions
  • FAQ: Frequently asked questions about CVE-2021-20263