NA

CVE-2023-1386

Published: 24/07/2023 Updated: 17/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1055174 qemu: CVE-2023-1386 Package: src:qemu; Maintainer for src:qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 1 Nov 2023 19:15:01 UTC Severity: important Tags: security, upstream Reply or subscribe to t ...