GPU VulnDB

Database/Kernel, userspace & hypervisor

QEMU (qemu-img): `qemu-img info` on an untrusted qcow2 image reaches arbitrary host file read/write

CVE-2024-4467Kernel, userspace & hypervisorcurated

Impact

qemu-img info on an untrusted qcow2 image reaches arbitrary host file read/write

Who can reach it

Tenant-supplied disk image processed by the control plane

What to do

Update qemu-img and never run it untrusted-unsandboxed; no reboot. Directly relevant to any "bring your own VM image" feature

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.