Description
Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1799-1 | New qemu packages fix several vulnerabilities |
EUVD |
EUVD-2008-0935 | Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T08:01:40.103Z
Reserved: 2008-02-25T00:00:00.000Z
Link: CVE-2008-0928
No data.
Status : Modified
Published: 2008-03-03T22:44:00.000
Modified: 2026-06-16T22:50:37.500
Link: CVE-2008-0928
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD