TROYANOSYVIRUS
Back to CVEs

CVE-2021-20263

LOW
3.3

Description

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.

CVE Details

CVSS v3.1 Score3.3
SeverityLOW
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/9/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

qemu:qemu

Weaknesses (CWE)

CWE-281CWE-281

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.