PT-2025-30721 · Qemu · Qemu
Published
2025-07-13
·
Updated
2025-12-18
·
CVE-2025-54566
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
QEMU versions through 10.0.3
QEMU version 7.2+dfsg-7+deb12u15
QEMU version 10.0.2+ds-2+deb13u1
Description:
QEMU contains a migration state inconsistency related to SR-IOV. Additionally, the update removes the usage of the C (Credential) flag for the binfmt misc registration within the
qemu-user package, which previously allowed for privilege escalation when running a suid/sgid binary under qemu-user. This affected cloud, virtualization, and container security.Recommendations:
QEMU versions through 10.0.3: Upgrade to a newer version.
QEMU version 7.2+dfsg-7+deb12u15: Upgrade to a newer version.
QEMU version 10.0.2+ds-2+deb13u1: Upgrade to a newer version.
If you previously relied on running suid/sgid foreign-architecture binaries under
qemu-user, adjust your deployment accordingly.Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qemu