SB2022032237 - SUSE update for qemu
Published: March 22, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Off-by-one (CVE-ID: CVE-2021-3930)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to an off-by-one error in the SCSI device emulation in QEMU. A remote user on the guest OS can can trigger an off-by-one error while processing MODE SELECT commands in mode_sense_page() if the 'page' argument is set to MODE_PAGE_ALLS (0x3f). Successful exploitation of the vulnerability may result in QEMU crash.
2) Incorrect default permissions (CVE-ID: CVE-2022-0358)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect QEMU virtio-fs shared file system daemon (virtiofsd) implementation. An attacker on the guest OS can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This can lead to privilege escalation within the guest OS.
The vulnerability exists due to incomplete fox for #VU13631 (CVE-2018-13405).
Remediation
Install update from vendor's website.