A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.
{ "vanir_signatures": [ { "id": "CVE-2020-35517-13be68d5", "signature_type": "Line", "target": { "file": "tools/virtiofsd/passthrough_ll.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "249749509298499509584371485767556501466", "12711853182023023152205651908599103558", "315258729476991449674869043710353997190", "204019443791831233187732787701240963246", "170281510680235729371742125984515929753", "164659170381731676902561706733556640937", "232319948962351838979387671832972659832", "305079778107006734855590619604593284998", "39305894112754925740096762295168641077", "276082376246000913282875299855255613144", "328343706111384061994435901361595455341", "219949455046928206170238000331014219943", "334406337309450458704185951770503366463", "293021897631797332104993338272819609744", "252115674339640699162879098670850943968", "228219910060695848906093012538773541096", "87754294341068678992578734537544486060", "160818454510647963155754149517232177224", "151192488196935969072428520761013750325", "123848594727535638370897045815574337890", "308896583069880168843792207651436176354", "59516531585813507903925809805615056773", "292321622711020180722545376535975169506", "43572313762544356283118112557704711241", "88010914881750275784855363694378048531", "8486564251605823966445302371346450272", "46847805536993130047683615076577617922", "252675941779889596571296404674957564794", "137994728785694869779579950183260600928", "238561854233320159021238617870068070754" ], "threshold": 0.9 }, "deprecated": false, "source": "https://github.com/qemu/qemu/commit/ebf101955ce8f8d72fba103b5151115a4335de2c" }, { "id": "CVE-2020-35517-8c795e23", "signature_type": "Function", "target": { "file": "tools/virtiofsd/passthrough_ll.c", "function": "setup_namespaces" }, "signature_version": "v1", "digest": { "length": 1732.0, "function_hash": "190598348096459599034904182258331633617" }, "deprecated": false, "source": "https://github.com/qemu/qemu/commit/ebf101955ce8f8d72fba103b5151115a4335de2c" } ] }