A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | * | 8.1.0 (excluding) |
Qemu | Ubuntu | bionic | * |
Qemu | Ubuntu | focal | * |
Qemu | Ubuntu | jammy | * |
Qemu | Ubuntu | kinetic | * |
Qemu | Ubuntu | lunar | * |
Qemu | Ubuntu | trusty | * |
Qemu | Ubuntu | xenial | * |