Security Advisory

CVE-2021-20181

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-13 15:24:15
Last updated 2024-08-03 17:30:07
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.