Quick Emulator(Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to a directory/path traversal issue. It could occur while creating or accessing files on a shared host directory. A privileged user inside guest could use this flaw to access undue files on the host. Upstream patches: ----------------- -> https://lists.gnu.org/archive/html/qemu-devel/2016-08/msg03917.html Reference: ---------- -> http://wiki.qemu.org/Documentation/9psetup -> http://www.openwall.com/lists/oss-security/2016/08/30/3
Acknowledgments: Name: Felix Wilhelm (ERNW)
*** Bug 1347350 has been marked as a duplicate of this bug. ***
Created xen tracking bugs for this issue: Affects: fedora-all [bug 1371400]
Created qemu tracking bugs for this issue: Affects: fedora-all [bug 1371399]