VYPR
Unrated severityNVD Advisory· Published Mar 3, 2008· Updated Apr 23, 2026

CVE-2008-0928

CVE-2008-0928

Description

Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.

Affected products

31
  • QEMU/Qemu29 versions
    cpe:2.3:a:qemu:qemu:0.1.0:*:*:*:*:*:*:*+ 28 more
    • cpe:2.3:a:qemu:qemu:0.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:qemu:qemu:0.9.1:*:*:*:*:*:*:*
  • osv-coords2 versions
    < 2.6.1-1.5+ 1 more
    • (no CPE)range: < 2.6.1-1.5
    • (no CPE)range: < 2.6.1-1.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

22

News mentions

0

No linked articles in our index yet.