A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Enterprise Linux For Nvidia 26 Subscribe
Enterprise Linux Nvidia Subscribe
Openshift Subscribe
Openshift Container Platform Subscribe
Openstack Subscribe
Openstack Platform Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Do not configure 9pfs/VirtFS filesystem sharing (-fsdev, -virtfs) on affected QEMU instances. If host-guest file sharing is required, use virtio-fs (virtiofsd) as an alternative, which does not use the vulnerable 9pfs code path.

History

Sun, 27 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Qemu
Qemu qemu
Redhat enterprise Linux For Nvidia 26
Redhat openshift Container Platform
Redhat openstack Platform
Vendors & Products Qemu
Qemu qemu
Redhat enterprise Linux For Nvidia 26
Redhat openshift Container Platform
Redhat openstack Platform

Sat, 26 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.
Title Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
First Time appeared Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
Weaknesses CWE-416
CPEs cpe:/a:redhat:enterprise_linux_nvidia:
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openstack:13
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat enterprise Linux Nvidia
Redhat openshift
Redhat openstack
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T13:50:26.440Z

Reserved: 2026-09-18T18:12:23.908Z

Link: CVE-2026-93834

cve-icon Vulnrichment

Updated: 2026-09-25T13:49:52.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T14:17:24.063

Modified: 2026-09-29T21:29:07.663

Link: CVE-2026-93834

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-22T00:00:00Z

Links: CVE-2026-93834 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T11:43:41Z

Weaknesses