Bug ID 1203370
Summary AUDIT-FIND: virtualbox: insecure permissions on /dev/vboxuser
Classification openSUSE
Product openSUSE Tumbleweed
Version Current
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter wolfgang.frisch@suse.com
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

The udev rule for VirtualBox guests sets the permissions of /dev/vboxuser to
0666. This device node is used for guest-host communication, and while there is
no known attack vector at the moment, it has been subject to security
vulnerabilities in the past: CVE-2018-3055 and CVE-2018-3085 [2].

In my opinion it would be prudent to change it back to 0660 and set the group
to `vboxguest`.

[1] https://build.opensuse.org/request/show/994651
[2] https://github.com/niklasb/3dpwn


You are receiving this mail because: