Impact
The QEMU Guest Agent’s guest-ssh-add-authorized-keys routine contains a vulnerability where an user can manipulate symbolic links to influence file creation or modification. By controlling the add-authorized-keys operation, the attacker can redirect file writes, gaining ownership of arbitrary root‑owned files or directories. This enables the elevation of privileges within the guest operating system. The flaw is categorized as CWE‑61, signifying a classic path traversal or relative path manipulation weakness.
Affected Systems
The vulnerability targets the QEMU‑Guest‑Agent component used by Red Hat Enterprise Linux 10, 6, 7, 8, 9, Red Hat Enterprise Linux for NVIDIA 26, and Red Hat OpenShift Container Platform 4. Any deployment of QEMU‑KVM that includes the guest-ssh-add-authorized-keys RPC without proper isolation may be affected, regardless of the specific minor version of the guest agent or host operating system.
Risk and Exploitability
The CVSS score of 7.3 places this issue in the high‑severity range. The EPSS score of <1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not included in the CISA KEV catalog. It is inferred that an attacker must have local access to the guest operating system in order to interact with the compromised function, making the attack vector local. Successful exploitation would enable the attacker to elevate privileges within the guest environment.
OpenCVE Enrichment