Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 618808 (CVE-2017-7493) - <app-emulation/qemu-2.9.0-r2: improper access control issue in VirtFS
Summary: <app-emulation/qemu-2.9.0-r2: improper access control issue in VirtFS
Status: RESOLVED FIXED
Alias: CVE-2017-7493
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B2 [glsa cve]
Keywords:
Depends on: CVE-2017-8380
Blocks:
  Show dependency tree
 
Reported: 2017-05-18 02:21 UTC by Michael Boyle
Modified: 2017-06-06 06:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Boyle 2017-05-18 02:21:37 UTC
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
Comment 1 Matthias Maier gentoo-dev 2017-05-18 04:23:16 UTC
Fixed in >=app-emulation/qemu-2.9.0-r2.
Vulnerable version left in tree app-emulation/qemu-2.8.1-r2

commit 33cfc7b69e6a25e0b66687e28f7b29ae1a43e2d4
Author: Matthias Maier <tamiko@gentoo.org>
Date:   Wed May 17 23:08:31 2017 -0500

    app-emulation/qemu: patch for CVE-2017-7493, bug #618808
    
    Package-Manager: Portage-2.3.5, Repoman-2.3.2
Comment 2 Yury German Gentoo Infrastructure gentoo-dev 2017-05-21 07:47:53 UTC
Added to an existing GLSA Request.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2017-06-06 06:50:44 UTC
This issue was resolved and addressed in
 GLSA 201706-03 at https://security.gentoo.org/glsa/201706-03
by GLSA coordinator Yury German (BlueKnight).