CVE-2023-1386
When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281
- Affected
- qemu/qemu · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2023-1386Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2223985Issue Tracking, Third Party Advisory
- https://github.com/advisories/GHSA-ppj8-867g-rgjr
- https://github.com/v9fs/linux/issues/29
- https://security.netapp.com/advisory/ntap-20230831-0005/
- https://access.redhat.com/security/cve/CVE-2023-1386Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2223985Issue Tracking, Third Party Advisory
- https://github.com/advisories/GHSA-ppj8-867g-rgjr
- https://github.com/v9fs/linux/issues/29
- https://security.netapp.com/advisory/ntap-20230831-0005/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.