Logo
componentqemu
Name
qemu
Version
9.2.0
Type
library
Description
-
Licenses
GPL-2.0LGPL-2.1MITBSD-3-ClauseBSD-2-ClauseOthers/BSD-1c
PURL
-
CPE
cpe:2.3:a:qemu:qemu:9.2.0:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
11.0.0

Patches#


#
Title
Author
Resolve
1
tests/fp/meson: don't build fp-bench test if fenv.h is
Dario Binacchi <dario.binacchi@amarulasolutions.com>
2
stubs: only build stubs for QAPI events when needed
Romain Naour <romain.naour@smile.fr>
3
sched_attr: Do not define for glibc >= 2.41
Khem Raj <raj.khem@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Exploitable
hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
Exploitable
hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
Exploitable
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Exploitable
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.