AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2017-15038

MEDIUM · CVSS 5.6 EPSS 0.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-10 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2017-15038
Severity
MEDIUM
CVSS
5.6
EPSS
0.28%

Original Filing — NVD Description

Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes.