Medium severity5.6NVD Advisory· Published Oct 10, 2017· Updated May 13, 2026
CVE-2017-15038
CVE-2017-15038
Description
Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.openwall.com/lists/oss-security/2017/10/06/1nvdMailing ListPatchThird Party Advisory
- lists.gnu.org/archive/html/qemu-devel/2017-10/msg00729.htmlnvdMailing ListPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlnvd
- usn.ubuntu.com/3575-1/nvd
- www.debian.org/security/2018/dsa-4213nvd
News mentions
0No linked articles in our index yet.