CVE-2023-2861: Qemu
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.
Affected products
- Qemu Qemu: before 8.1.0 (fixed in 8.1.0)
Published 2023-12-06. Last modified 2026-06-17.