CVE-2016-9602 PUBLISHED

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

EPSS 1.30% · 79.6th percentile

Risk Scores

EPSS Score
1.30%
79.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSqemu0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6
Ubuntu:16.04:LTSqemu0, 1:2.3+dfsg-5ubuntu9, 1:2.3+dfsg-5ubuntu10

Timeline

References

Open in Interactive Console →