Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1799-1 | New qemu packages fix several vulnerabilities |
EUVD |
EUVD-2008-0935 | Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:01:40.103Z
Reserved: 2008-02-25T00:00:00
Link: CVE-2008-0928
No data.
Status : Deferred
Published: 2008-03-03T22:44:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-0928
OpenCVE Enrichment
No data.
Debian DSA
EUVD