Back to bug 2219266

Who When What Removed Added
TEJ RATHI 2023-07-03 06:59:08 UTC CC ddepaula, jen, jferlan, jmaloy, knoel, mkenneth, mrezanin, mst, pbonzini, virt-maint, ymankad
Mauro Matteo Cascella 2023-07-03 08:02:51 UTC Blocks 2175653
Severity medium low
Summary TRIAGE-CVE-2023-2861 qemu: Insufficient access control in 9pfs CVE-2023-2861 QEMU: 9pfs: improper access control on special files
Priority medium low
Alias TRIAGE-CVE-2023-2861 CVE-2023-2861
Mauro Matteo Cascella 2023-07-03 08:03:07 UTC Depends On 2219306
Mauro Matteo Cascella 2023-07-03 08:12:42 UTC Doc Text A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
Product Security DevOps Team 2023-07-04 07:46:01 UTC Status NEW CLOSED
Resolution --- NOTABUG
Last Closed 2023-07-04 07:46:01 UTC

Back to bug 2219266