A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qemu | Aug 22, 2024 | May 13, 2021 |
| Debian | — | Upgrade qemu | Feb 19, 2021 | Feb 19, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade qemu-img | Jan 28, 2022 | May 13, 2021 |
| Oracle_linux | — | Upgrade qemu-system-x86-coreUpgrade qemu-commonUpgrade qemu-kvmUpgrade qemu-system-aarch64-coreUpgrade ivshmem-toolsUpgrade qemu-system-aarch64Upgrade qemu-block-glusterUpgrade qemu-block-rbdUpgrade qemu-block-iscsiUpgrade qemu-kvm-coreUpgrade qemu-system-x86Upgrade qemu-imgUpgrade qemu | Mar 12, 2021 | Jan 14, 2021 |
| Suse | — | Upgrade qemu-audio-spiceUpgrade qemu-s390Upgrade qemu-ui-gtkUpgrade qemu-sgabiosUpgrade qemu-kvmUpgrade qemu-chardev-baumUpgrade qemu-hw-display-virtio-gpuUpgrade qemu-block-rbdUpgrade qemu-block-sshUpgrade qemu-ppcUpgrade qemu-vgabiosUpgrade qemu-hw-usb-hostUpgrade qemu-s390xUpgrade qemu-guest-agentUpgrade qemu-chardev-spiceUpgrade kvmUpgrade qemuUpgrade qemu-hw-usb-smartcardUpgrade qemu-hw-s390x-virtio-gpu-ccwUpgrade qemu-langUpgrade qemu-microvmUpgrade qemu-block-curlUpgrade qemu-extraUpgrade qemu-block-nfsUpgrade qemu-vhost-user-gpuUpgrade qemu-x86Upgrade qemu-ipxeUpgrade qemu-toolsUpgrade qemu-audio-sdlUpgrade qemu-armUpgrade qemu-hw-display-qxlUpgrade qemu-block-dmgUpgrade qemu-ui-spice-appUpgrade qemu-slofUpgrade qemu-ui-openglUpgrade qemu-seabiosUpgrade qemu-skibootUpgrade qemu-ksmUpgrade qemu-hw-usb-redirectUpgrade qemu-ui-spice-coreUpgrade qemu-linux-userUpgrade qemu-audio-paUpgrade qemu-hw-display-virtio-gpu-pciUpgrade qemu-testsuiteUpgrade qemu-block-glusterUpgrade qemu-audio-ossUpgrade qemu-hw-display-virtio-vgaUpgrade qemu-audio-alsaUpgrade qemu-block-iscsiUpgrade qemu-accel-tcg-x86Upgrade qemu-ui-cursesUpgrade qemu-ui-sdl | Mar 2, 2021 | Feb 8, 2021 |
| Ubuntu | — | Upgrade qemu-system-common (Ubuntu Pro)Upgrade qemu-system-arm (Ubuntu Pro)Upgrade qemu-system-x86Upgrade qemu-kvm (Ubuntu Pro)Upgrade qemu-system-sparc (Ubuntu Pro)Upgrade qemu-user-static (Ubuntu Pro)Upgrade qemu-system-x86 (Ubuntu Pro)Upgrade qemu-system-ppc (Ubuntu Pro)Upgrade qemu-user (Ubuntu Pro)Upgrade qemu-system-misc (Ubuntu Pro)Upgrade qemu-system-mipsUpgrade qemu-system (Ubuntu Pro)Upgrade qemu-system-aarch64 (Ubuntu Pro)Upgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-aarch64Upgrade qemu-keymaps (Ubuntu Pro)Upgrade qemu-system-ppcUpgrade qemu (Ubuntu Pro)Upgrade qemu-system-s390xUpgrade qemu-system-sparcUpgrade qemu-utils (Ubuntu Pro)Upgrade qemu-system-armUpgrade qemu-guest-agent (Ubuntu Pro)Upgrade qemu-system-x86-microvmUpgrade qemu-system-x86-xenUpgrade qemu-common (Ubuntu Pro)Upgrade qemu-system-mips (Ubuntu Pro) | Feb 9, 2021 | Feb 8, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub