Description
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2282-1 | qemu-kvm security update |
EUVD |
EUVD-2011-2511 | The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host. |
Ubuntu USN |
USN-1177-1 | QEMU vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T23:00:34.288Z
Reserved: 2011-06-15T00:00:00.000Z
Link: CVE-2011-2527
No data.
Status : Modified
Published: 2012-06-21T15:55:09.863
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-2527
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN