Database/Kernel, userspace & hypervisor
QEMU (qemu-img): `qemu-img info` on an untrusted qcow2 image reaches arbitrary host file read/write
CVSS 7.8CVE-2024-4467Kernel, userspace & hypervisorcurated
Impact
qemu-img info on an untrusted qcow2 image reaches arbitrary host file read/write
Who can reach it
Tenant-supplied disk image processed by the control plane
What to do
Update qemu-img and never run it untrusted-unsandboxed; no reboot. Directly relevant to any "bring your own VM image" feature
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): Freeing a scheduler job dereferences the VM it belongs to, but the final exec-queueCVE-2024-44978 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery path runs without the state lock, soCVE-2024-45019 · Linux kernel mlx5_core TX timeout devlink health reporterHigh
- Arm Mali GPU kernel driver: Use-after-free in the Bifrost/Valhall GPU kernel driverCVE-2024-4610 · Arm Mali GPU kernel driverHigh
- Linux kernel (drivers/gpu/drm/xe): The preempt-fence lock lives inside the exec queue, but the queue reference isCVE-2024-46683 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/pci): Pci_bus_lock() locked every device on the bus except the bridge itself, so a secondary busCVE-2024-46750 · Linux kernel (drivers/pci)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): Missing or insufficient validation of user-suppliedCVE-2024-46803 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.