Privilege Escalation Vulnerability in QEMU Virtio-FS Daemon
CVE-2022-0358
What is CVE-2022-0358?
A vulnerability exists in the QEMU virtio-fs shared file system daemon where a local guest user can create files in shared directories with unintended group ownership. This occurs when a directory is set with SGID for a specific group and is writable by users outside of that group. Exploiting this flaw can enable an unprivileged user within the guest system to access resources intended for the root group, leading to potential privilege escalation. Additionally, a malicious local user could misuse the executable file created within the guest to escalate privileges on the host system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
QEMU/virtiofsd Fixed in qemu v6.2.0-7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
