CVE-2026-93834
Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
Description
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.
In plain language
AI Worth attentionThis is a serious flaw in virtual-machine hosting on affected Red Hat platforms; small businesses should act if they run guest virtual machines using shared folders.
A guest user with access to QEMU/KVM 9pfs can trigger a use-after-free race between Tlcreate and Twalk requests, bypass shared-directory traversal restrictions, and potentially escape the VM as the QEMU process user.
What to do now
- Check whether you run Red Hat virtual machines with shared folders enabled through QEMU/KVM 9pfs.
- Identify every affected Red Hat platform and restrict untrusted users from those guest systems while you assess exposure.
- No fixed version or vendor patch information is currently available; contact Red Hat for the supported remediation and deploy it when released.
- If you cannot patch yet, disable 9pfs shared folders or remove access to the affected virtual machines where practical.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-93834 and every CVE in our database. Create a free account — no credit card required.
Create Free Account