« List of all CVEs

CVE-2016-9602

Published: 4/26/2018 Last updated: 8/6/2024 Reserved: 11/23/2016

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.6 High CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Opam packages affected (2)

conf-qemu-img nbd-tool

Products affected (1)

Product Vendor Version
Qemu unspecified 16.12.5a

References (16)