CVE-2021-20263
Dashboard / Vulnerabilities / CVE-2021-20263
CVE-2021-20263
Published: 9 Mar 2021Last Modified: 15 Mar 2026
Summary:
Details: A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged executable in the guest. In rare circumstances, this flaw could be used by a malicious user to elevate their privileges within the guest.
References: https://security.gentoo.org/glsa/202208-27, https://security.netapp.com/advisory/ntap-20210507-0002/, https://www.openwall.com/lists/oss-security/2021/03/08/1, https://bugzilla.redhat.com/show_bug.cgi?id=1933668
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
