Lucene search

K
cvelistRedhatCVELIST:CVE-2021-20263
HistoryMar 09, 2021 - 5:17 p.m.

CVE-2021-20263

2021-03-0917:17:43
CWE-281
redhat
www.cve.org

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new ‘xattrmap’ option may cause the ‘security.capability’ xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.

CNA Affected

[
  {
    "product": "QEMU",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "qemu 5.2.50"
      }
    ]
  }
]

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%