QEMU Affected By Another Security Vulnerability

CVE-2015-3209 is the new QEMU vulnerability going public today whereby a heap overflow could happen within the PCNET controller and allow a guest to host scape.
Per the details in the advisory, "A guest which has access to an emulated PCNET network device (e.g. with 'model=pcnet' in their VIF configuration) can exploit this vulnerability to take over the qemu process elevating its privilege to that of the qemu process."
QEMU patches are available to address this vulnerability in this important piece of the open-source Linux virtualization stack.
3 Comments
