Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-20263
HistoryMar 09, 2021 - 6:15 p.m.

Design/Logic Flaw

2021-03-0918:15:00
PRIOn knowledge base
www.prio-n.com
5

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new ‘xattrmap’ option may cause the ‘security.capability’ xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.

CPENameOperatorVersion
qemuge5.0.0
qemult5.2.50

4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%