{"id":"CVE-2026-93834","published":"2026-09-25T14:17:24.063","lastModified":"2026-09-29T21:29:07.663","description":"A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-93834","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537939","tags":[]},{"url":"https://gitlab.com/qemu-project/qemu/-/work_items/4491","tags":[]},{"url":"https://gitlab.com/qemu-project/qemu/-/work_items/4491","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a use-after-free vulnerability in QEMU's 9pfs subsystem, allowing a malicious guest user to escape the shared directory boundary and perform arbitrary file read/write and code execution.","exploitability":"Exploitation requires a race condition between the main thread and a worker thread, making it moderately difficult. Precondition is the presence of concurrent Tlcreate and Twalk requests.","blast_radius":"If exploited, this can lead to significant real-world impact, including data theft, host compromise, and potential VM escape.","remediation":"Upgrade to the latest QEMU version (e.g., 'Upgrade to 5.2.0 or later').","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","vm-escape","file-access","patch-recommended"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:06:05.196Z"}}