A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Enterprise Linux Nvidia Subscribe
Openshift Subscribe
Openstack Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Do not configure 9pfs/VirtFS filesystem sharing (-fsdev, -virtfs) on affected QEMU instances. If host-guest file sharing is required, use virtio-fs (virtiofsd) as an alternative, which does not use the vulnerable 9pfs code path.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.
Title Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
Weaknesses CWE-416
CPEs cpe:/a:redhat:enterprise_linux_nvidia:
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openstack:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T13:50:26.440Z

Reserved: 2026-09-18T18:12:23.908Z

Link: CVE-2026-93834

cve-icon Vulnrichment

Updated: 2026-09-25T13:49:52.580Z

cve-icon NVD

Status : Received

Published: 2026-09-25T14:17:24.063

Modified: 2026-09-25T14:17:24.063

Link: CVE-2026-93834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses