ZDI-CAN-27261: ZDI-25-884: QEMU uefi-vars Uninitialized Memory Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of QEMU. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2025-8860.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-27261?
ZDI-CAN-27261 has a significant severity level, indicating a potential risk to sensitive information disclosure in QEMU systems.
How do I fix ZDI-CAN-27261?
To remediate ZDI-CAN-27261, update your QEMU installation to the latest version that includes security patches.
Who is affected by ZDI-CAN-27261?
ZDI-CAN-27261 affects installations of QEMU that allow local attackers to exploit the vulnerability.
What type of information can be disclosed due to ZDI-CAN-27261?
ZDI-CAN-27261 can lead to the disclosure of sensitive information from the affected QEMU guest systems.
What is needed to exploit ZDI-CAN-27261?
An attacker must have the ability to execute high-privileged code on the target guest system to exploit ZDI-CAN-27261.