OESA-2022-1772
Dashboard / Vulnerabilities / OESA-2022-1772
Summary: qemu security update
Details: QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed. Security Fix(es): A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.(CVE-2021-4158) A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. A local guest user can create files in the directories shared by virtio-fs with unintended group ownership in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of the group. This issue allows a malicious user to trigger CVE-2018-13405 to obtain sensitive information or potentially escalate their privileges on the system.(CVE-2022-0358)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1772, https://nvd.nist.gov/vuln/detail/CVE-2021-4158, https://nvd.nist.gov/vuln/detail/CVE-2022-0358
Affected packages
Package
Name: qemu
Purl: pkg:rpm/openEuler/qemu&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
