Logo
componentqemu
Name
qemu
Version
10.1.3-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:qemu:qemu:10.1.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
openwrt-25.12
10.1.2-r1

Patches#


#
Title
Author
Resolve
1
qga: invoke separate applets for guest shutdown modes
Vladimir Ermakov <vooon341@gmail.com>
2
util/mmap-alloc: fix missing MAP_SYNC
Yousong Zhou <yszhou4tech@gmail.com>
3
configure: allow disable fortify_source
Yousong Zhou <yszhou4tech@gmail.com>
4
fix meson cross-build compiler sanity check
Vladimir Ermakov <vooon341@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Exploitable
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by malicious users in the guest to elevate their privileges within the guest and help a host local user to elevate privileges on the host.
Exploitable
A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This issue occurs while processing controller commands due to a DMA reentry issue. This flaw allows a guest user or process to consume CPU cycles or crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.