Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-1386
HistoryJul 24, 2023 - 4:15 p.m.

Design/Logic Flaw

2023-07-2416:15:00
PRIOn knowledge base
www.prio-n.com
4
logic flaw
9p passthrough filesystem
qemu
executable file
suid
sgid
privileged bits
elevation of privileges

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.

CPENameOperatorVersion
fedoraeq38

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%