Description
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3759-1 | qemu security update |
EUVD |
EUVD-2023-34310 | A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder. |
Ubuntu USN |
USN-6567-1 | QEMU vulnerabilities |
Ubuntu USN |
USN-8172-1 | kvmtool vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-02T06:33:05.791Z
Reserved: 2023-05-24T07:54:12.009Z
Link: CVE-2023-2861
Updated: 2024-08-02T06:33:05.791Z
Status : Modified
Published: 2023-12-06T07:15:41.430
Modified: 2024-11-21T07:59:26.520
Link: CVE-2023-2861
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN