A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest via virtio-fs device. If the guest opens the maximum number of file descriptors under the shared directory, a denial of service may occur. This flaw allows a guest user/process to cause this denial of service on the host.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | May 4, 2020 |
| Gentoo Linux | — | Upgrade app-emulation/qemu. | Nov 12, 2020 | May 4, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 4, 2020 |
| Suse | — | Upgrade qemu-x86Upgrade qemu-ksmUpgrade qemu-audio-alsaUpgrade qemu-chardev-baumUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-langUpgrade qemu-ppcUpgrade qemu-audio-paUpgrade qemu-audio-spiceUpgrade qemu-block-sshUpgrade qemu-ipxeUpgrade qemu-ui-openglUpgrade qemu-block-iscsiUpgrade qemu-ui-spice-appUpgrade qemu-toolsUpgrade qemu-hw-usb-redirectUpgrade qemu-chardev-spiceUpgrade qemu-ui-gtkUpgrade qemu-ui-spice-coreUpgrade qemu-block-curlUpgrade qemu-seabiosUpgrade qemu-guest-agentUpgrade qemu-block-rbdUpgrade qemu-skibootUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-s390xUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-kvmUpgrade qemuUpgrade qemu-armUpgrade qemu-hw-display-qxlUpgrade qemu-vgabiosUpgrade qemu-sgabiosUpgrade qemu-ui-curses | Feb 4, 2022 | May 4, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub