Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Vulnerability Description
Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because the guest agent socket provides tunneling for arbitrary addresses, including Unix socket addresses for privileged daemons like D-Bus. This issue is fixed in version 2.1.3.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
缺省权限不正确
Vulnerability Title
Linux Machines Lima 权限许可和访问控制问题漏洞
Vulnerability Description
Linux Machines Lima是Linux Machines公司开源的一款能在 macOS 等系统上启动 Linux 虚拟机、并自动实现文件共享与端口转发的工具,核心定位是让用户便捷地运行容器(支持 containerd、Docker、Kubernetes 等)。 Linux Machines Lima 2.1.3之前版本存在权限许可和访问控制问题漏洞,该漏洞源于当guest agent启用时,虚拟机中任意用户可访问/run/lima-guestagent.sock,可能导致在虚拟机中利用root
CVSS Information
N/A
Vulnerability Type
N/A