Database/Kernel, userspace & hypervisor
QEMU (qemu-img): `qemu-img info` on an untrusted qcow2 image reaches arbitrary host file read/write
CVE-2024-4467Kernel, userspace & hypervisorcurated
Impact
qemu-img info on an untrusted qcow2 image reaches arbitrary host file read/write
Who can reach it
Tenant-supplied disk image processed by the control plane
What to do
Update qemu-img and never run it untrusted-unsandboxed; no reboot. Directly relevant to any "bring your own VM image" feature
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.