[Bug 1203370] New: AUDIT-FIND: virtualbox: insecure permissions on /dev/vboxuser
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 Bug ID: 1203370 Summary: AUDIT-FIND: virtualbox: insecure permissions on /dev/vboxuser Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: wolfgang.frisch@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- The udev rule for VirtualBox guests sets the permissions of /dev/vboxuser to 0666. This device node is used for guest-host communication, and while there is no known attack vector at the moment, it has been subject to security vulnerabilities in the past: CVE-2018-3055 and CVE-2018-3085 [2]. In my opinion it would be prudent to change it back to 0660 and set the group to `vboxguest`. [1] https://build.opensuse.org/request/show/994651 [2] https://github.com/niklasb/3dpwn -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370
Wolfgang Frisch
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c1
--- Comment #1 from OBSbugzilla Bot
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c2
--- Comment #2 from OBSbugzilla Bot
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c5
--- Comment #5 from OBSbugzilla Bot
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c6
--- Comment #6 from OBSbugzilla Bot
participants (1)
-
bugzilla_noreply@suse.com