A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | May 13, 2021 |
| Debian | — | Upgrade qemu | Feb 19, 2021 | Feb 19, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Jan 28, 2022 | May 13, 2021 |
| Oracle_linux | — | Upgrade qemu-system-aarch64-coreUpgrade qemu-kvmUpgrade qemu-system-aarch64Upgrade qemu-commonUpgrade ivshmem-toolsUpgrade qemu-system-x86-coreUpgrade qemu-block-rbdUpgrade qemu-imgUpgrade qemuUpgrade qemu-system-x86Upgrade qemu-kvm-coreUpgrade qemu-block-glusterUpgrade qemu-block-iscsi | Mar 12, 2021 | Jan 14, 2021 |
| Suse | — | Upgrade qemu-ksmUpgrade qemu-ui-cursesUpgrade qemu-slofUpgrade qemu-skibootUpgrade qemu-block-iscsiUpgrade qemu-audio-alsaUpgrade qemu-hw-display-qxlUpgrade qemu-block-dmgUpgrade qemu-ui-spice-appUpgrade qemu-seabiosUpgrade qemu-block-glusterUpgrade qemu-accel-tcg-x86Upgrade qemu-hw-display-virtio-vgaUpgrade qemu-ui-sdlUpgrade qemu-audio-ossUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-audio-paUpgrade qemu-ui-spice-coreUpgrade qemu-armUpgrade qemu-testsuiteUpgrade qemu-linux-userUpgrade qemu-ui-openglUpgrade qemu-hw-usb-redirectUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-block-sshUpgrade qemu-ipxeUpgrade qemu-chardev-spiceUpgrade qemuUpgrade qemu-guest-agentUpgrade qemu-extraUpgrade qemu-x86Upgrade qemu-block-nfsUpgrade qemu-microvmUpgrade qemu-langUpgrade qemu-sgabiosUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-block-curlUpgrade qemu-s390Upgrade qemu-ppcUpgrade qemu-audio-spiceUpgrade qemu-hw-usb-smartcardUpgrade qemu-vhost-user-gpuUpgrade qemu-audio-sdlUpgrade qemu-ui-gtkUpgrade qemu-toolsUpgrade qemu-kvmUpgrade kvmUpgrade qemu-block-rbdUpgrade qemu-vgabiosUpgrade qemu-hw-usb-hostUpgrade qemu-s390xUpgrade qemu-chardev-baum | Mar 2, 2021 | Feb 8, 2021 |
| Ubuntu | — | Upgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro)Upgrade qemu-system-x86-xenUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-system-sparcUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-system-s390xUpgrade qemu (Ubuntu Pro)Upgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-aarch64Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-system-ppcUpgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-mipsUpgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-user (Ubuntu Pro)Upgrade qemu-system-sparc (Ubuntu Pro) | Feb 9, 2021 | Feb 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub