CVE-2016-9602: Debian Linux

High severity, CVSS 8.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Qemu Qemu: before 2.9 (fixed in 2.9)

Published 2018-04-26. Last modified 2026-06-17.