An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Oct 10, 2023 | Aug 28, 2023 |
| Ubuntu | — | Upgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-system-x86-xenUpgrade qemu-system-x86-microvmUpgrade qemu-system-x86Upgrade qemu-system-miscUpgrade qemu-system-sparcUpgrade qemu-systemUpgrade qemu-system-xenUpgrade qemu-system-mipsUpgrade qemu-system-ppcUpgrade qemu | Jan 9, 2024 | Aug 28, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub