The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle_linux | — | Upgrade qemu-imgUpgrade qemu-kvmUpgrade qemu-kvm-tools | Oct 16, 2024 | Jun 21, 2012 |
| Suse | — | Upgrade kvm | Dec 12, 2013 | Jun 21, 2012 |
| Ubuntu | — | Upgrade qemu-kvmUpgrade qemu-kvm-extrasUpgrade qemu-kvm-extras-static | Nov 8, 2024 | Jun 21, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub