Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24608
HistoryApr 10, 2020 - 12:59 a.m.

Privilege Escalation

2020-04-1000:59:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

26.0%

qemu-kvm is vulnerable to privilege escalation. The vulnerability exists as it was found that the virtio subsystem in qemu-kvm did not properly validate virtqueue in and out requests from the guest. A privileged guest user could use this flaw to trigger a buffer overflow, allowing them to crash the guest (denial of service) or, possibly, escalate their privileges on the host.