A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the time lstat(2) was called in usb_mtp_object_alloc, a classical TOCTTOU problem. An attacker with write access to the host filesystem shared with a guest can use this property to navigate the host filesystem in the context of the QEMU process and read any file the QEMU process has access to. Access to the filesystem may be local or via a network share protocol such as CIFS.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Base Score: 5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Mar 12, 2019 | Dec 13, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-kvmUpgrade qemu-block-glusterUpgrade qemu-ui-cursesUpgrade qemu-ui-sdlUpgrade qemu-imgUpgrade qemu-system-aarch64Upgrade qemu-audio-sdlUpgrade qemu-commonUpgrade qemu-block-nfsUpgrade qemu-audio-ossUpgrade qemu-system-aarch64-coreUpgrade qemu-block-curlUpgrade qemu-ui-gtkUpgrade qemu-block-sshUpgrade qemu-audio-paUpgrade qemu-audio-alsaUpgrade qemu-block-iscsiUpgrade qemu-block-rbdUpgrade qemu-block-dmg | Aug 28, 2019 | Dec 13, 2018 |
| Oracle_linux | — | Upgrade qemu-system-aarch64-coreUpgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-imgUpgrade ivshmem-toolsUpgrade qemu-system-x86Upgrade qemu-kvmUpgrade qemu-commonUpgrade qemu-block-rbdUpgrade qemuUpgrade qemu-system-aarch64Upgrade qemu-system-x86-coreUpgrade qemu-kvm-core | May 15, 2019 | Dec 13, 2018 |
| Suse | — | Upgrade qemu-chardev-spiceUpgrade qemu-skibootUpgrade qemu-ksmUpgrade qemu-armUpgrade qemu-audio-paUpgrade qemu-testsuiteUpgrade qemu-seabiosUpgrade qemu-linux-userUpgrade qemu-ui-openglUpgrade qemu-ui-spice-appUpgrade qemu-block-dmgUpgrade qemu-block-glusterUpgrade qemu-audio-ossUpgrade qemu-audio-alsaUpgrade qemu-hw-display-qxlUpgrade qemu-ui-spice-coreUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-hw-usb-redirectUpgrade qemu-block-iscsiUpgrade qemu-ui-cursesUpgrade qemu-s390Upgrade qemu-ppcUpgrade qemu-block-sshUpgrade qemu-audio-spiceUpgrade qemu-block-rbdUpgrade qemu-toolsUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-s390xUpgrade qemu-guest-agentUpgrade qemu-ipxeUpgrade qemu-x86Upgrade qemu-ui-gtkUpgrade qemu-extraUpgrade qemu-kvmUpgrade qemu-vgabiosUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-sgabiosUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemuUpgrade qemu-chardev-baumUpgrade qemu-block-curlUpgrade qemu-microvmUpgrade qemu-lang | Feb 20, 2019 | Dec 13, 2018 |
| Ubuntu | — | Upgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-guiUpgrade qemu-systemUpgrade qemu-system-mipsUpgrade qemu-system-miscUpgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-ppcUpgrade qemu-system-data | Apr 3, 2019 | Dec 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub