CVE-2026-8348
Public on 2026-07-29
Modified on 2026-07-29
Description
In QEMU's 9pfs (virtio-9p) implementation, the TXATTRCREATE and TXATTRWALK request handlers do not limit the number of simultaneously open xattr FIDs. Each xattr FID allocates a
host memory buffer for the extended attribute value. A malicious privileged guest user with direct 9p server access can exploit this by repeatedly creating xattr FIDs without closing
them, leading to unbounded host memory consumption and eventual host memory exhaustion (denial of service). This vulnerability has existed since QEMU v0.14.0-rc0 and is fixed in
v11.0.3 and v10.0.12.
host memory buffer for the extended attribute value. A malicious privileged guest user with direct 9p server access can exploit this by repeatedly creating xattr FIDs without closing
them, leading to unbounded host memory consumption and eventual host memory exhaustion (denial of service). This vulnerability has existed since QEMU v0.14.0-rc0 and is fixed in
v11.0.3 and v10.0.12.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | qemu | Pending Fix | ||
| Amazon Linux 2023 | qemu | Not Affected | ||
| Amazon Linux 2 - Core | qemu-guest-agent | Not Affected | ||
| Amazon Linux 2 - Core | qemu-kvm | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |