VYPR
Critical severity9.8NVD Advisory· Published Nov 6, 2017· Updated May 13, 2026

CVE-2017-16638

CVE-2017-16638

Description

The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.

Affected products

1
  • cpe:2.3:a:vde_project:vde:*:r4:*:*:*:gentoo:*:*
    Range: <2.3.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.