CVE-2026-8348

Public on 2026-07-29
Modified on 2026-07-29
Description
In QEMU's 9pfs (virtio-9p) implementation, the TXATTRCREATE and TXATTRWALK request handlers do not limit the number of simultaneously open xattr FIDs. Each xattr FID allocates a
host memory buffer for the extended attribute value. A malicious privileged guest user with direct 9p server access can exploit this by repeatedly creating xattr FIDs without closing
them, leading to unbounded host memory consumption and eventual host memory exhaustion (denial of service). This vulnerability has existed since QEMU v0.14.0-rc0 and is fixed in
v11.0.3 and v10.0.12.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core qemu Pending Fix
Amazon Linux 2023 qemu Not Affected
Amazon Linux 2 - Core qemu-guest-agent Not Affected
Amazon Linux 2 - Core qemu-kvm Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H