A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write access to the host filesystem shared with a guest can use this property to navigate the host filesystem in the context of the QEMU process and read any file the QEMU process has access to. Access to the filesystem may be local or via a network share protocol such as CIFS.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Base Score: 5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Mar 12, 2019 | Dec 13, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-commonUpgrade qemu-audio-sdlUpgrade qemu-block-glusterUpgrade qemu-block-nfsUpgrade qemu-system-aarch64Upgrade qemu-imgUpgrade qemu-kvmUpgrade qemu-ui-sdlUpgrade qemu-ui-cursesUpgrade qemu-block-iscsiUpgrade qemu-audio-paUpgrade qemu-block-dmgUpgrade qemu-audio-ossUpgrade qemu-audio-alsaUpgrade qemu-block-curlUpgrade qemu-block-rbdUpgrade qemu-ui-gtkUpgrade qemu-block-sshUpgrade qemu-system-aarch64-core | Aug 28, 2019 | Dec 13, 2018 |
| Oracle_linux | — | Upgrade qemu-commonUpgrade qemu-kvm-coreUpgrade qemuUpgrade qemu-block-rbdUpgrade qemu-system-x86-coreUpgrade qemu-system-aarch64Upgrade qemu-kvmUpgrade qemu-block-glusterUpgrade qemu-system-x86Upgrade qemu-block-iscsiUpgrade qemu-system-aarch64-coreUpgrade qemu-imgUpgrade ivshmem-tools | May 15, 2019 | Dec 13, 2018 |
| Suse | — | Upgrade qemu-vgabiosUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-extraUpgrade qemu-toolsUpgrade qemu-audio-spiceUpgrade qemu-block-sshUpgrade qemuUpgrade qemu-microvmUpgrade qemu-chardev-baumUpgrade qemu-ui-gtkUpgrade qemu-sgabiosUpgrade qemu-kvmUpgrade qemu-s390xUpgrade qemu-block-rbdUpgrade qemu-x86Upgrade qemu-s390Upgrade qemu-guest-agentUpgrade qemu-block-curlUpgrade qemu-ipxeUpgrade qemu-ppcUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-langUpgrade qemu-hw-usb-redirectUpgrade qemu-ksmUpgrade qemu-hw-display-qxlUpgrade qemu-linux-userUpgrade qemu-seabiosUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-ui-spice-appUpgrade qemu-armUpgrade qemu-audio-paUpgrade qemu-audio-ossUpgrade qemu-block-glusterUpgrade qemu-testsuiteUpgrade qemu-audio-alsaUpgrade qemu-ui-spice-coreUpgrade qemu-block-dmgUpgrade qemu-block-iscsiUpgrade qemu-chardev-spiceUpgrade qemu-ui-openglUpgrade qemu-skibootUpgrade qemu-ui-curses | Feb 20, 2019 | Dec 13, 2018 |
| Ubuntu | — | Upgrade qemu-system-sparcUpgrade qemu-system-dataUpgrade qemu-system-aarch64Upgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-guiUpgrade qemu-system-mipsUpgrade qemu-system-ppcUpgrade qemu-system-x86Upgrade qemu-system-armUpgrade qemu-system-s390x | Apr 3, 2019 | Dec 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub