Vendor
medium
advisory
QEMU Memory Corruption and Denial of Service Vulnerability
1 TTPA vulnerability in QEMU allows a remote, authenticated attacker to trigger memory corruption or a denial-of-service condition, impacting system availability.
QEMU
denial-of-service
virtualization
1t
high
advisory
QEMU Guest Agent Vulnerability Allows Local Privilege Escalation (CVE-2026-12080)
2 TTPs 1 CVEA local unprivileged user within a QEMU guest can exploit CVE-2026-12080, a vulnerability in the QEMU Guest Agent's 'guest-ssh-add-authorized-keys' command handler, by manipulating symbolic links through a directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race to gain ownership of arbitrary root-owned files or directories, leading to root access within the guest OS.
QEMU Guest Agent +1
privilege-escalation
vulnerability
qemu
guest-agent
2t
1c
updated