CVE-2017-7493: High severity Qemu Qemu vulnerability
Last updated 24 July 2024
Other sources
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
— Launchpad
Quick Emulator(Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode.
A guest user could use this flaw to escalate their privileges inside guest.
Upstream patches: ----------------- -> https://lists.gnu.org/archive/html/qemu-devel/2017-05/msg03663.html
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2017/05/17/6
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-7493?
CVE-2017-7493 is a vulnerability in Quick Emulator (Qemu) that allows a guest user to escalate their privileges.
How does CVE-2017-7493 occur?
CVE-2017-7493 occurs when there is improper access control while accessing virtfs metadata files in mapped-file security mode.
What is the severity of CVE-2017-7493?
CVE-2017-7493 has a severity level of medium.
Which software versions are affected by CVE-2017-7493?
Qemu versions 2.0.0+dfsg-2ubuntu1.35, 1:2.5+dfsg-5ubuntu10.15, 1:2.8+dfsg-3ubuntu2.4, and various versions of Debian are affected by CVE-2017-7493.
How can CVE-2017-7493 be fixed?
To fix CVE-2017-7493, update to the latest version of Qemu provided by the respective software vendor.