CVE-2020-35517

Name
CVE-2020-35517
Description
A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1915823
Exploit https://lists.gnu.org/archive/html/qemu-devel/2021-01/msg05461.html
Exploit https://www.openwall.com/lists/oss-security/2021/01/22/1
Release Notes https://github.com/qemu/qemu/commit/ebf101955ce8f8d72fba103b5151115a4335de2c
Third Party Advisory https://security.netapp.com/advisory/ntap-20210312-0002/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:qemu:qemu:-:*:*:*:*:*:*:* qemu == None == -
cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* qemu >= 5.0.0 <= 5.2.50

Vulnerable and fixed packages

Source package Branch Version Maintainer Status