Logo
vulnerabilityCVE-2023-1386
Name
CVE-2023-1386
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
qemu
Exploitable

Vulnerability Ratings#


3.3
CVSSv31
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
9.2.0
Exploitable
buildroot
master
11.0.0
Exploitable
openwrt
master
10.1.3-r2
Exploitable
yocto
kirkstone
6.2.0
Exploitable
yocto
master
11.0.1
Exploitable
yocto
scarthgap
8.2.7
Exploitable