{"id":"GHSA-f7qw-jj9c-rpq9","summary":"In Lima, a malicious disk image could read a single file on the host filesystem as a qcow2/vmdk backing file","details":"\u003e **Note**\n\u003e\n\u003e The official templates of Lima, and the well-known third party products (Colima, Rancher Desktop, and Finch) are *unlikely* to be affected by this issue.\n\n### Impact\nA virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host.\n\nTo exploit this issue, the attacker has to embed the target file path (an absolute or a relative path from the instance directory) in a malicious disk image, as the [qcow2 (or vmdk) backing file path string](https://gitlab.com/qemu-project/qemu/-/blob/v8.0.0/docs/interop/qcow2.txt#L23-L34).\nAs Lima refuses to run as the root, it is practically impossible for the attacker to read the entire host disk via `/dev/rdiskN`.\nAlso, practically, the attacker cannot read at least the first 512 bytes (MBR) of the target file.\n\n### Patches\nPatched in Lima v0.16.0, by prohibiting using a backing file path in the VM base image.\n\n### Workarounds\nDo not use an untrusted disk image.","aliases":["CVE-2023-32684","GO-2023-1803"],"modified":"2024-08-20T20:59:12.040604Z","published":"2023-05-31T23:38:28Z","database_specific":{"nvd_published_at":"2023-05-30T18:15:10Z","cwe_ids":["CWE-552"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-05-31T23:38:28Z"},"references":[{"type":"WEB","url":"https://github.com/lima-vm/lima/security/advisories/GHSA-f7qw-jj9c-rpq9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32684"},{"type":"WEB","url":"https://github.com/lima-vm/lima/commit/01dbd4d9cabe692afa4517be3995771f0ebb38a5"},{"type":"PACKAGE","url":"https://github.com/lima-vm/lima"},{"type":"WEB","url":"https://github.com/lima-vm/lima/releases/tag/v0.16.0"}],"affected":[{"package":{"name":"github.com/lima-vm/lima","ecosystem":"Go","purl":"pkg:golang/github.com/lima-vm/lima"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.16.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-f7qw-jj9c-rpq9/GHSA-f7qw-jj9c-rpq9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N"}]}